CVE-2007-0108: Medium severity Novell client vulnerability
Published Jan 9, 2007
·Updated
nwgina.dll in Novell Client 4.91 SP3 for Windows 2000/XP/2003 does not delete user profiles during a Terminal Service or Citrix session, which allows remote authenticated users to invoke alternate user profiles.
Affected Software
1 affected component
Novell client=4.91-sp3
Event History
Jan 9, 2007
CVE Published
12:28 AM
Data Sourced
via NVD·12:28 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0108?
CVE-2007-0108 is classified as a medium severity vulnerability.
2
How do I fix CVE-2007-0108?
To address CVE-2007-0108, upgrade to a patched version of Novell Client beyond 4.91 SP3.
3
What systems are affected by CVE-2007-0108?
CVE-2007-0108 affects Novell Client 4.91 SP3 on Windows 2000, XP, and 2003 systems.
4
What exploit exists for CVE-2007-0108?
CVE-2007-0108 allows remote authenticated users to access alternate user profiles during Terminal Service or Citrix sessions.
5
Is CVE-2007-0108 a local or remote vulnerability?
CVE-2007-0108 is considered a remote vulnerability because it can be exploited by remote authenticated users.