First published: Fri May 26 2006(Updated: )
Novell Client for Windows 4.8 and 4.9 does not restrict access to the clipboard contents while a machine is locked, which allows users with physical access to read the current clipboard contents by pasting them into the "User Name" field on the login prompt.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell NetWare Client | =4.8 | |
Novell NetWare Client | =4.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2612 has a medium severity rating due to the risk of unauthorized access to clipboard contents on physically accessible locked machines.
To fix CVE-2006-2612, upgrade to a later version of the Novell Client that addresses clipboard access issues.
CVE-2006-2612 affects Novell Client for Windows versions 4.8 and 4.9.
Yes, CVE-2006-2612 can lead to data leakage, as an attacker with physical access can view sensitive information stored in the clipboard.
Yes, physical access to the machine is required to exploit the vulnerability described in CVE-2006-2612.