Novell Messenger Server < 2.2.1 Memory Information Disclosure
Medium Nessus Network Monitor Plugin ID 6057
SynopsisThe remote host has an instant messaging server product installed that is affected by an information disclosure vulnerability.
DescriptionThe remote host is running Novell Messenger Server, formerly Groupwise Messenger, an instant messaging server application.
Versions of Novell Messenger Server earlier than 2.2.1 are potentially affected by an information disclosure vulnerability whereby a remote, unauthenticated attacker could send commands that would force the Messenger server process to return the contents of arbitrary memory locations. This data could potentially include strings containing the credentials used by Messenger to authenticate to directory services.
SolutionUpgrade to Novell Messenger 2.2.1 or later.