First published: Tue Jan 09 2007(Updated: )
nwgina.dll in Novell Client 4.91 SP3 for Windows 2000/XP/2003 does not delete user profiles during a Terminal Service or Citrix session, which allows remote authenticated users to invoke alternate user profiles.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell Client | =4.91-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0108 is classified as a medium severity vulnerability.
To address CVE-2007-0108, upgrade to a patched version of Novell Client beyond 4.91 SP3.
CVE-2007-0108 affects Novell Client 4.91 SP3 on Windows 2000, XP, and 2003 systems.
CVE-2007-0108 allows remote authenticated users to access alternate user profiles during Terminal Service or Citrix sessions.
CVE-2007-0108 is considered a remote vulnerability because it can be exploited by remote authenticated users.