First published: Sat Feb 19 2005(Updated: )
Tarantella Secure Global Desktop Enterprise Edition 4.00 and 3.42, and Tarantella Enterprise 3 3.40 and 3.30, when using RSA SecurID and multiple users have the same username, reveals sensitive information during authentication, which allows remote attackers to identify valid usernames and the authentication scheme.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Tarantella Enterprise | =3.40 | |
Oracle Tarantella Enterprise | =3.30 | |
Oracle Virtualization Secure Global Desktop | =enterprise_3.42 | |
Oracle Virtualization Secure Global Desktop | =enterprise_4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0486 has a medium severity rating due to its potential to expose sensitive authentication information.
To fix CVE-2005-0486, update to the latest versions of Tarantella Secure Global Desktop and Tarantella Enterprise that address this vulnerability.
Affected software versions for CVE-2005-0486 include Tarantella Secure Global Desktop 4.00 and 3.42, and Tarantella Enterprise 3.30 and 3.40.
Yes, CVE-2005-0486 allows remote attackers to identify valid usernames due to the information revealed during authentication.
CVE-2005-0486 can compromise user privacy by disclosing sensitive authentication information that may be utilized in unauthorized access attempts.