Novell GroupWise GrpWise.EXE Authentication Credentials Persistence Weakness
BID:13997
Info
Novell GroupWise GrpWise.EXE Authentication Credentials Persistence Weakness
| Bugtraq ID: | 13997 |
| Class: | Design Error |
| CVE: |
CVE-2005-2620 CVE-2005-2620 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 20 2005 12:00AM |
| Updated: | Mar 19 2015 09:16AM |
| Credit: | Discovery of this issue is credited to "Security Team" <[email protected]>. |
| Vulnerable: |
Novell Groupwise 6.5.4 Novell Groupwise 6.5.2 Novell Groupwise 6.5 SP2 Novell Groupwise 6.5 SP1 Novell Groupwise 6.5 Novell Groupwise 6.0 SP4 Novell Groupwise 6.0 SP3 Novell Groupwise 6.0 SP2 Novell Groupwise 6.0 SP1 Novell Groupwise 6.0 Novell Groupwise 5.5 Novell Groupwise 5.2 DameWare Development NT Utilities 4.9 DameWare Development NT Utilities 4.8 DameWare Development NT Utilities 3.0 |
| Not Vulnerable: |
Novell Groupwise 7.0 |
Discussion
Novell GroupWise GrpWise.EXE Authentication Credentials Persistence Weakness
A problem with Novell GroupWise may allow the recovery of sensitive information.
Novell GroupWise 'grpWise.exe' does not safely handle authentication credential information. As a result, a local user may be able to recover authentication passwords.
A problem with Novell GroupWise may allow the recovery of sensitive information.
Novell GroupWise 'grpWise.exe' does not safely handle authentication credential information. As a result, a local user may be able to recover authentication passwords.
Exploit / POC
Novell GroupWise GrpWise.EXE Authentication Credentials Persistence Weakness
No exploit is required.
No exploit is required.
Solution / Fix
Novell GroupWise GrpWise.EXE Authentication Credentials Persistence Weakness
Solution:
Novell reports that this issue will be addressed in GroupWise 6.5 SP5. There are also field test files available to address this issue. Please see the referenced Novell TID for instructions on obtaining these test files.
Novell security advisory NOVL-2005-10098073 is available. Novell GroupWise 7 is not vulnerable to this issue. Please see the referenced advisory for further information.
Solution:
Novell reports that this issue will be addressed in GroupWise 6.5 SP5. There are also field test files available to address this issue. Please see the referenced Novell TID for instructions on obtaining these test files.
Novell security advisory NOVL-2005-10098073 is available. Novell GroupWise 7 is not vulnerable to this issue. Please see the referenced advisory for further information.
References
Novell GroupWise GrpWise.EXE Authentication Credentials Persistence Weakness
References:
References:
- DameWare Homepage (DameWare Development)
- Novell GroupWise Homepage (Novell)
- TID10098073 GroupWise Password Temporarily Stored in local workstation Memory (Novell)
- Dameware NT Utilities and MiniRemote Control <= 4.9 vulnerability (Jordi Corrales
) - Novell GroupWise Plain Text Password Vulnerability. ("Security Team"
)