[原文]Novell Client for Windows 4.8 and 4.9 does not restrict access to the clipboard contents while a machine is locked, which allows users with physical access to read the current clipboard contents by pasting them into the "User Name" field on the login prompt.
Novell Client Login Field Clipboard Content Disclosure
Physical Access Required
Loss of Confidentiality
Novell Client contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered due to the Novell client Login dialog box failure to restrict access to the contents of the clipboard when the system is "locked". It can be possible to disclose the text contents of the current user's clipboard by pasting it into the "User Name" field, or to change the clipboard's content by performing a copy from the "User Name" field information.
Currently, there are no known upgrades or patches to correct this issue. It is possible to correct the flaw by implementing the following workaround:
manualy clear clipboard before locking and after unlocking system.