Novell NetWare 6.5 SP 1.1, when installing or upgrading using the Overlay CDs and performing a custom installation with OpenSSH, includes sensitive password information in the (1) NIOUTPUT.TXT and (2) NI.LOG log files, which might allow local users to obtain the passwords.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/15600 | vdb entry |
http://www.securityfocus.com/bid/9934 | vdb entry patch |
http://support.novell.com/cgi-bin/search/searchtid.cgi?/2968534.htm | patch vendor advisory |
http://secunia.com/advisories/11188 | third party advisory patch vendor advisory |