First published: Tue Dec 05 2006(Updated: )
Format string vulnerability in Novell Modular Authentication Services (NMAS) in the Novell Client 4.91 SP2 and SP3 allows users with physical access to read stack and memory contents via format string specifiers in the Username field of the logon window.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell NetWare Client | =4.91-sp3 | |
Novell NetWare Client | =4.91-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6306 is classified as a medium severity vulnerability.
To resolve CVE-2006-6306, upgrade to a later version of the Novell Client that does not exhibit this vulnerability.
CVE-2006-6306 affects Novell Client versions 4.91 SP2 and SP3.
CVE-2006-6306 is a format string vulnerability that can lead to exposure of stack and memory contents.
CVE-2006-6306 can be exploited by users with physical access to the affected system.