漏洞信息详情
Novell Modular Authentication Services (NMAS)格式化字符串漏洞
漏洞简介
Novell Client中的Novell Modular Authentication Services (NMAS)存在格式化字符串漏洞,具有物理访问权的用户可通过在登录窗口中的用户名字段中的格式化字符串限定符来读取栈和内存内容。
漏洞公告
参考网址
来源: XF
名称: novell-nmas-format-string(30644)
链接:http://xforce.iss.net/xforce/xfdb/30644
来源: BUGTRAQ
名称: 20061201 Layered Defense Advisory: Novell Client 4.91 Format String Vulnerability
链接:http://www.securityfocus.com/archive/1/archive/1/453176/100/0/threaded
来源: MISC
链接:http://www.layereddefense.com/Novell01DEC.html
来源: FULLDISC
名称: 20061201 Layered Defense Advisory: Novell Client 4.91 Format String Vulnerability
链接:http://lists.grok.org.uk/pipermail/full-disclosure/2006-December/051038.html
来源: secure-support.novell.com
链接:https://secure-support.novell.com/KanisaPlatform/Publishing/372/3546910_f.SAL_Public.html
来源: VUPEN
名称: ADV-2006-4987
链接:http://www.frsirt.com/english/advisories/2006/4987
来源: support.novell.com
链接:http://support.novell.com/cgi-bin/search/searchtid.cgi?/2974876.htm
来源: support.novell.com
链接:http://support.novell.com/cgi-bin/search/searchtid.cgi?/2974872.htm
来源: SECTRACK
名称: 1017377
链接:http://securitytracker.com/id?1017377
来源: SREASON
名称: 1970
链接:http://securityreason.com/securityalert/1970
来源: SECUNIA
名称: 23363
链接:http://secunia.com/advisories/23363
受影响实体
- Novell Client:4.91:Sp2<!--2000-1-1-->
- Novell Client:4.91:Sp3<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...