First published: Tue Jun 12 2007(Updated: )
NMASINST in Novell Modular Authentication Service (NMAS) 3.1.2 and earlier on NetWare logs its invoking command line to NMASINST.LOG, which might allow local users to obtain the admin username and password by reading this file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell Modular Authentication Service | <=3.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3200 is considered a high severity vulnerability due to the potential exposure of admin credentials.
To fix CVE-2007-3200, upgrade to a version of Novell Modular Authentication Service later than 3.1.2 that addresses this logging issue.
CVE-2007-3200 affects local users of Novell Modular Authentication Service versions 3.1.2 and earlier on NetWare.
The impact of CVE-2007-3200 is that it may allow local users to read sensitive admin credentials from the NMASINST.LOG file.
Yes, CVE-2007-3200 is classified as an authentication vulnerability since it compromises the integrity of admin authentication.