Executive brief
A vulnerability in the login utility of Novell Netware 4.0 and 4.01 could allow a local user to gain unauthorized access to the system. The software temporarily saves sensitive login credentials, including usernames and passwords, to the disk in a way that other local users can access. This could lead to full account takeover and unauthorized access to corporate data stored on the network.
Technical details
The LOGIN.EXE utility in Novell Netware versions 4.0 and 4.01 contains an information disclosure vulnerability. During the authentication process, the program writes sensitive credentials, including plaintext or recoverable usernames and passwords, to a temporary file on the local disk. A local attacker with access to the filesystem can monitor for these temporary files to intercept credentials. This allows for privilege escalation or unauthorized access to other user accounts. The vulnerability was originally identified in 1993 and is addressed in later patches or versions of the Netware operating system.
Affected products
- Novell Netware 4.0, 4.01
Timeline
- 1993-09-16: disclosed: Initial disclosure date recorded in NVD
- 1993-12-31: advisory: Included in CERT 1993 annual advisory summary