CVE-2006-0997: Medium severity SUSE Open Enterprise Server vulnerability
The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) permits encryption with a NULL key, which results in cleartext communication that allows remote attackers to read an SSL protected session by sniffing network traffic.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0997?
CVE-2006-0997 is considered a high severity vulnerability due to its potential for exploitation allowing cleartext communications.
How do I fix CVE-2006-0997?
To mitigate CVE-2006-0997, ensure that you're using a secure configuration that does not permit NULL key encryption in your SSL settings.
What versions are affected by CVE-2006-0997?
CVE-2006-0997 affects Novell NetWare 6.5 and Novell Open Enterprise Server versions 6.5, including various service packs.
What kind of attacks can CVE-2006-0997 lead to?
CVE-2006-0997 can allow remote attackers to intercept and read SSL protected communications, leading to potential data breaches.
Is there a patch for CVE-2006-0997?
Yes, vendors may provide patches or updates for CVE-2006-0997, so it is crucial to check with Novell for available security updates.