Title: Novell NetWare NILE.NLM SSL Server Encryption Downgrade Weakness
Info
Disclosure
Mar 17, 2006
Discovery
Unknown
Dates
Exploit
Unknown
Solution
Unknown
Description
Novell NetWare and Novell Open Enterprise Server contains a flaw that may allow a malicious user to force server to negotiate a less secure SSL connection. The issue is triggered because SSL server implementation in NILE.NLM allows a client to force the server to use weak encryption by stating that a weak cipher is required for client compatibility. It is possible that the flaw may allow remote attackers to decrypt contents of an SSL protected session resulting in a loss of confidentiality.
Classification
Location:
Remote / Network Access
Attack Type:
Cryptographic
Impact:
Loss of Confidentiality
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified
Solution
Currently, there are no known workarounds or upgrades to correct this issue. However, vendor has released a patch NILE65SP5A.EXE to address this vulnerability.