Novell iChain Mini FTP Server 2.3 displays different error messages if a user exists or not, which allows remote attackers to obtain sensitive information and facilitates brute force attacks.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.infobyte.com.ar/adv/ISR-04.html | vendor advisory |
http://marc.info/?l=bugtraq&m=111091027000721&w=2 | mailing list |
http://www.securityfocus.com/bid/12811 | vdb entry vendor advisory |
http://secunia.com/advisories/14607 | third party advisory vendor advisory |