Description
grpWise.exe for Novell GroupWise client 5.5 through 6.5.2 stores the password in plaintext in memory, which allows attackers to obtain the password using a debugger or another mechanism to read process memory.
Affected products
- Novell / groupwise6.0 – 6.0
- Novell / groupwise6.5 – 6.5
- Novell / groupwise6.5.2 – 6.5.2
References
- MISChttp://www.securiteam.com/windowsntfocus/5UP0Q0UG0I.html
- MISChttp://support.novell.com/cgi-bin/search/searchtid.cgi?/10098073.htm
- MISChttp://archives.neohapsis.com/archives/fulldisclosure/2005-08/0858.html
- MISChttp://securitytracker.com/id?1014247
- MISChttp://www.securityfocus.com/bid/13997
- MISChttp://support.novell.com/cgi-bin/search/searchtid.cgi?/2972056.htm
- MAILING_LISThttp://marc.info/?l=bugtraq&m=112431139225724&w=2
- MISChttp://www.osvdb.org/17470
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/21075
- MISChttp://archives.neohapsis.com/archives/bugtraq/2005-06/0158.html