OSVDB ID: 24048

Title: Novell NetWare NILE.NLM SSL Server Encryption Downgrade Weakness

Info

Disclosure

Mar 17, 2006

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

Novell NetWare and Novell Open Enterprise Server contains a flaw that may allow a malicious user to force server to negotiate a less secure SSL connection. The issue is triggered because SSL server implementation in NILE.NLM allows a client to force the server to use weak encryption by stating that a weak cipher is required for client compatibility. It is possible that the flaw may allow remote attackers to decrypt contents of an SSL protected session resulting in a loss of confidentiality.

Classification

Location: Remote / Network Access
Attack Type: Cryptographic
Impact: Loss of Confidentiality
Exploit: Exploit Unknown
Disclosure: OSVDB Verified

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, vendor has released a patch NILE65SP5A.EXE to address this vulnerability.

Products

Novell, Inc.

Novell NetWare

6.5 SP4
6.5 SP3
6.5 SP2
6.5 SP1
6.5
6.5 SP1.1(a)
6.5 SP1.1(b)

Novell Open Enterprise Server

0

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/24048