Novell Netware Screen Saver Local Authentication Bypass Vulnerability
BID:11892
Info
Novell Netware Screen Saver Local Authentication Bypass Vulnerability
| Bugtraq ID: | 11892 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 13 2004 12:00AM |
| Updated: | Dec 13 2004 12:00AM |
| Credit: | Discovery is credited to Adam Gray <[email protected]>. |
| Vulnerable: |
Novell Netware 6.5 SP1.1(b) Novell Netware 6.5 SP1.1(a) Novell Netware 6.5 SP1 Novell Netware 6.5 Novell Netware 6.0 SP3 Novell Netware 6.0 SP2 Novell Netware 6.0 SP1 Novell Netware 6.0 Novell Netware 5.1 SP6 Novell Netware 5.1 SP4 Novell Netware 5.1 SP5 Novell Netware 5.1 Novell Netware 5.0 SP5 Novell Netware 5.0 |
| Not Vulnerable: | |
Discussion
Novell Netware Screen Saver Local Authentication Bypass Vulnerability
Novell Netware is reported prone to a local authentication bypass vulnerability. This issue can allow an attacker to gain unauthorized access to a computer.
The operating system may be locked with the SCRSAVER NLM to deny access to the console. Typically, only a user with supervisor privileges in the e-directory tree is able to unlock the computer, however an attacker can bypass this restriction by invoking the Netware debugger and shutting down the screen saver.
Novell Netware is reported prone to a local authentication bypass vulnerability. This issue can allow an attacker to gain unauthorized access to a computer.
The operating system may be locked with the SCRSAVER NLM to deny access to the console. Typically, only a user with supervisor privileges in the e-directory tree is able to unlock the computer, however an attacker can bypass this restriction by invoking the Netware debugger and shutting down the screen saver.
Exploit / POC
Novell Netware Screen Saver Local Authentication Bypass Vulnerability
An exploit is not required to leverage this vulnerability.
An exploit is not required to leverage this vulnerability.
Solution / Fix
Novell Netware Screen Saver Local Authentication Bypass Vulnerability
Solution:
Novell has released Technical Information Document TID2969741 containing the BorderManager ICSA Compliance Kit v5.0d, which includes a patch for this issue. Please see TID2969741 in Web references for more information.
Solution:
Novell has released Technical Information Document TID2969741 containing the BorderManager ICSA Compliance Kit v5.0d, which includes a patch for this issue. Please see TID2969741 in Web references for more information.
References
Novell Netware Screen Saver Local Authentication Bypass Vulnerability
References:
References: