CVE-2005-0797: Infoleak
Novell iChain Mini FTP Server 2.3 displays different error messages if a user exists or not, which allows remote attackers to obtain sensitive information and facilitates brute force attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-0797?
CVE-2005-0797 is considered a medium severity vulnerability due to its potential impact on information disclosure and brute force attacks.
How do I fix CVE-2005-0797?
To fix CVE-2005-0797, it is recommended to upgrade to the latest version of Novell iChain that addresses this vulnerability.
What type of attack does CVE-2005-0797 facilitate?
CVE-2005-0797 facilitates brute force attacks due to the varying error messages that indicate whether a user exists.
Which versions of Novell iChain are affected by CVE-2005-0797?
CVE-2005-0797 affects versions 2.2, 2.3, and their respective service pack releases prior to the patch.
Can CVE-2005-0797 be exploited remotely?
Yes, CVE-2005-0797 can be exploited remotely, allowing attackers to gain sensitive information.