Novell Client login form enables reading and writing from and to the clipboard of the logged-in user

2006.05.27
Risk: Low
Local: Yes
Remote: No
CWE: CWE-Other


CVSS Base Score: 2.1/10
Impact Subscore: 2.9/10
Exploitability Subscore: 3.9/10
Exploit range: Local
Attack complexity: Low
Authentication: No required
Confidentiality impact: Partial
Integrity impact: None
Availability impact: None

> Suggested Risk Level: Low. > > Type of Risk: Information Leakage, Information Injection, Unauthorized > Access. > > Affected Software: Novell Client for Windows, versions 4.9 and 4.8 (On > windows XP Pro and Windows 2000 Workstation). > This versions are the only one tested, thus other version may be vulnerable > as well. > > Local / Remote activation: Local. > > Summary: > > 1. Anyone with access to the computer's local operating system console, one > using the Novell client login screen (when the console is locked), can view > a textual content of the clipboard of the locally logged in user, by > performing a paste command into the "user name" field of the login form. We thank Eitan Caspi for his precise analysis of the problem and for thoroughly working with us on it. Specifically, we confirm the low severity rating of this information leakage, which is why we allow ourselves more time than usual to investigate an entirely satisfactory solution to the problem. If there will be an update for this issue, our customers and users will benefit from it through the regular channels. The publication of Eitan's findings is the correct next step - again, we thank him for his valuable work. [...] > Eitan Caspi > Israel Roman Drahtmller, Novell/SUSE Security. -- - - | Roman Drahtmller <draht (at) novell (dot) com [email concealed]> // "You don't need eyes to see, | Security Architect Phone: // you need vision!" | Novell - SUSE Linux +49-911-740530 // Maxi Jazz, Faithless | - -


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top