Secunia Logo
 
CVE Reference: CVE-2006-0997
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-0997

Description:
The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) permits encryption with a NULL key, which results in cleartext communication that allows remote attackers to read an SSL protected session by sniffing network traffic.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/25380

ST
  1015799

SAID
  Secunia Advisory: SA19324

OSVDB
  24046

CONFIRM
  http://support.novell.com/cgi-bin/search/searchtid.cgi?10100633.htm

BID
  17176


Return to the previous page.