CVE-2005-0486: Medium severity Tarantella Tarantella Enterprise vulnerability
Tarantella Secure Global Desktop Enterprise Edition 4.00 and 3.42, and Tarantella Enterprise 3 3.40 and 3.30, when using RSA SecurID and multiple users have the same username, reveals sensitive information during authentication, which allows remote attackers to identify valid usernames and the authentication scheme.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-0486?
CVE-2005-0486 has a medium severity rating due to its potential to expose sensitive authentication information.
How do I fix CVE-2005-0486?
To fix CVE-2005-0486, update to the latest versions of Tarantella Secure Global Desktop and Tarantella Enterprise that address this vulnerability.
What are the affected software versions for CVE-2005-0486?
Affected software versions for CVE-2005-0486 include Tarantella Secure Global Desktop 4.00 and 3.42, and Tarantella Enterprise 3.30 and 3.40.
Can CVE-2005-0486 allow username enumeration?
Yes, CVE-2005-0486 allows remote attackers to identify valid usernames due to the information revealed during authentication.
What impact does CVE-2005-0486 have on user privacy?
CVE-2005-0486 can compromise user privacy by disclosing sensitive authentication information that may be utilized in unauthorized access attempts.