CVE-2006-6306: Low severity novell client vulnerability
Published Dec 5, 2006
·Updated
Format string vulnerability in Novell Modular Authentication Services (NMAS) in the Novell Client 4.91 SP2 and SP3 allows users with physical access to read stack and memory contents via format string specifiers in the Username field of the logon window.
Affected Software
2 affected components
Novell client=4.91-sp2
Novell client=4.91-sp3
Event History
Dec 5, 2006
CVE Published
11:28 AM
Data Sourced
via NVD·11:28 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-6306?
CVE-2006-6306 is classified as a medium severity vulnerability.
2
How do I fix CVE-2006-6306?
To resolve CVE-2006-6306, upgrade to a later version of the Novell Client that does not exhibit this vulnerability.
3
What software is affected by CVE-2006-6306?
CVE-2006-6306 affects Novell Client versions 4.91 SP2 and SP3.
4
What type of vulnerability is CVE-2006-6306?
CVE-2006-6306 is a format string vulnerability that can lead to exposure of stack and memory contents.
5
Who can exploit CVE-2006-6306?
CVE-2006-6306 can be exploited by users with physical access to the affected system.