CVE-2004-2414
Last modified
CVE-2004-2414 is a vulnerability of currently unknown severity. Novell NetWare 6.5 SP 1.1, when installing or upgrading using the Overlay CDs and performing a custom installation with OpenSSH, includes sensitive password information in the (1) NIOUTPUT.TXT and (2) NI.LOG log files, which might allow local users to obtain the passwords.. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
Novell NetWare 6.5 SP 1.1, when installing or upgrading using the Overlay CDs and performing a custom installation with OpenSSH, includes sensitive password information in the (1) NIOUTPUT.TXT and (2) NI.LOG log files, which might allow local users to obtain the passwords.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Novell | Netware | 6.5 | Sp1.1a |
References
- http://secunia.com/advisories/11188Patch, Vendor Advisory
- http://support.novell.com/cgi-bin/search/searchtid.cgi?/2968534.htmPatch, Vendor Advisory
- http://secunia.com/advisories/11188Patch, Vendor Advisory
- http://support.novell.com/cgi-bin/search/searchtid.cgi?/2968534.htmPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-2414?
How severe is CVE-2004-2414?
How do I fix CVE-2004-2414?
Are you affected by CVE-2004-2414?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
