Novell Client Username Information Disclosure and Denial Of Service Vulnerabilities
BID:21385
Info
Novell Client Username Information Disclosure and Denial Of Service Vulnerabilities
| Bugtraq ID: | 21385 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 01 2006 12:00AM |
| Updated: | Dec 13 2006 08:33PM |
| Credit: | Deral Heiland is credited with discovering this vulnerability. |
| Vulnerable: |
Novell Client 4.91 SP3 Novell Client 4.91 SP2 |
| Not Vulnerable: | |
Discussion
Novell Client Username Information Disclosure and Denial Of Service Vulnerabilities
Novell Client is prone to information-disclosure and denial-of-service vulnerabilities because the application fails to properly sanitize user-supplied input.
Successful exploits may allow remote attackers to retrieve sensitive information or to cause denial-of-service conditions. Other attacks may also be possible.
Novell Client 4.91 is vulnerable; other versions may also be affected.
Novell Client is prone to information-disclosure and denial-of-service vulnerabilities because the application fails to properly sanitize user-supplied input.
Successful exploits may allow remote attackers to retrieve sensitive information or to cause denial-of-service conditions. Other attacks may also be possible.
Novell Client 4.91 is vulnerable; other versions may also be affected.
Exploit / POC
Novell Client Username Information Disclosure and Denial Of Service Vulnerabilities
Attackers may exploit this issue by gaining access to the vulnerable application.
Attackers may exploit this issue by gaining access to the vulnerable application.
Solution / Fix
Novell Client Username Information Disclosure and Denial Of Service Vulnerabilities
Solution:
The vendor has released multiple patches to address this issue. Please see the references for more information.
Novell Client 4.91 SP3
Novell Client 4.91 SP2
Solution:
The vendor has released multiple patches to address this issue. Please see the references for more information.
Novell Client 4.91 SP3
-
Novell 491psp3_loginw32.exe;
http://support.novell.com/servlet/filedownload/sec/ftf/491psp3_loginw3 2.exe
Novell Client 4.91 SP2
-
Novell 491psp2_login_5.exe
http://support.novell.com/servlet/filedownload/sec/ftf/491psp2_login_5 .exe
References
Novell Client Username Information Disclosure and Denial Of Service Vulnerabilities
References:
References: