Format string vulnerability in Novell Modular Authentication Services (NMAS) in the Novell Client 4.91 SP2 and SP3 allows users with physical access to read stack and memory contents via format string specifiers in the Username field of the logon window.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:22
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.grok.org.uk/pipermail/full-disclosure/2006-December/051038.html - Vendor Advisory | |
References | () http://secunia.com/advisories/23363 - | |
References | () http://securityreason.com/securityalert/1970 - | |
References | () http://securitytracker.com/id?1017377 - | |
References | () http://support.novell.com/cgi-bin/search/searchtid.cgi?/2974872.htm - | |
References | () http://support.novell.com/cgi-bin/search/searchtid.cgi?/2974876.htm - | |
References | () http://www.layereddefense.com/Novell01DEC.html - Vendor Advisory | |
References | () http://www.securityfocus.com/archive/1/453176/100/0/threaded - | |
References | () http://www.vupen.com/english/advisories/2006/4987 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/30644 - | |
References | () https://secure-support.novell.com/KanisaPlatform/Publishing/372/3546910_f.SAL_Public.html - |
Information
Published : 2006-12-05 11:28
Updated : 2024-11-21 00:22
NVD link : CVE-2006-6306
Mitre link : CVE-2006-6306
CVE.ORG link : CVE-2006-6306
JSON object : View
Products Affected
novell
- client
CWE