LOW
Format string vulnerability in Novell Modular Authentication Services (NMAS) in the Novell Client 4.91 SP2 and SP3 allows users with physical access to read stack and memory contents via format string specifiers in the Username field of the logon window
Published Dec 5, 2006
1.2
LOWCVSS 2.0
EPSS 0.36%
Description
Format string vulnerability in Novell Modular Authentication Services (NMAS) in the Novell Client 4.91 SP2 and SP3 allows users with physical access to read stack and memory contents via format string specifiers in the Username field of the logon window.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (11)
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-December/051038.html mailing-listx_refsource_FULLDISCVendor Advisory
- http://secunia.com/advisories/23363 third-party-advisoryx_refsource_SECUNIA
- http://securityreason.com/securityalert/1970 third-party-advisoryx_refsource_SREASON
- http://securitytracker.com/id?1017377 vdb-entryx_refsource_SECTRACK
- http://support.novell.com/cgi-bin/search/searchtid.cgi?/2974872.htm x_refsource_CONFIRM
- http://support.novell.com/cgi-bin/search/searchtid.cgi?/2974876.htm x_refsource_CONFIRM
- http://www.layereddefense.com/Novell01DEC.html x_refsource_MISCVendor Advisory
- http://www.securityfocus.com/archive/1/453176/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.vupen.com/english/advisories/2006/4987 vdb-entryx_refsource_VUPEN
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30644 vdb-entryx_refsource_XF
- https://secure-support.novell.com/KanisaPlatform/Publishing/372/3546910_f.SAL_Public.html x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| http://lists.grok.org.uk/pipermail/full-disclosure/2006-December/051038.html | mailing-listx_refsource_FULLDISCVendor Advisory | |
| http://secunia.com/advisories/23363 | third-party-advisoryx_refsource_SECUNIA | |
| http://securityreason.com/securityalert/1970 | third-party-advisoryx_refsource_SREASON | |
| http://securitytracker.com/id?1017377 | vdb-entryx_refsource_SECTRACK | |
| http://support.novell.com/cgi-bin/search/searchtid.cgi?/2974872.htm | x_refsource_CONFIRM | |
| http://support.novell.com/cgi-bin/search/searchtid.cgi?/2974876.htm | x_refsource_CONFIRM | |
| http://www.layereddefense.com/Novell01DEC.html | x_refsource_MISCVendor Advisory | |
| http://www.securityfocus.com/archive/1/453176/100/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| http://www.vupen.com/english/advisories/2006/4987 | vdb-entryx_refsource_VUPEN | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/30644 | vdb-entryx_refsource_XF | |
| https://secure-support.novell.com/KanisaPlatform/Publishing/372/3546910_f.SAL_Public.html | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 5, 2006
Updated Aug 7, 2024
Reserved Dec 5, 2006
Link CVE-2006-6306
CISA Vulnrichment
Updated n/a