CVE-2006-0998: Medium severity SUSE Open Enterprise Server vulnerability
The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) sometimes selects a weak cipher instead of an available stronger cipher, which makes it easier for remote attackers to sniff and decrypt an SSL protected session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0998?
CVE-2006-0998 has a moderate severity level due to the potential for remote attackers to sniff and decrypt SSL protected sessions.
How do I fix CVE-2006-0998?
To fix CVE-2006-0998, update your Novell NetWare or Open Enterprise Server to the latest patched version.
Which software is affected by CVE-2006-0998?
CVE-2006-0998 affects Novell NetWare 6.5 and Novell Open Enterprise Server (OES) on various service packs.
What impact does CVE-2006-0998 have on SSL sessions?
CVE-2006-0998 can result in the selection of weaker ciphers for SSL sessions, compromising the confidentiality of data.
Who is at risk due to CVE-2006-0998?
Organizations using vulnerable versions of Novell NetWare or OES are at risk from potential remote attacks targeting SSL sessions.