Vulnerability Name: | CVE-2006-0591 (CCN-24590) | ||||||||||||
Assigned: | 2006-02-07 | ||||||||||||
Published: | 2006-02-07 | ||||||||||||
Updated: | 2018-10-19 | ||||||||||||
Summary: | The crypt_gensalt functions for BSDI-style extended DES-based and FreeBSD-sytle MD5-based password hashes in crypt_blowfish 0.4.7 and earlier do not evenly and randomly distribute salts, which makes it easier for attackers to guess passwords from a stolen password file due to the increased number of collisions. | ||||||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||
CVSS v2 Severity: | 1.2 Low (CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:N/A:N) 0.9 Low (Temporal CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
1.9 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||||||
Vulnerability Type: | CWE-310 | ||||||||||||
Vulnerability Consequences: | Other | ||||||||||||
References: | Source: SGI Type: UNKNOWN 20060602-01-U Source: MITRE Type: CNA CVE-2006-0591 Source: MISC Type: UNKNOWN http://cvsweb.openwall.com/cgi/cvsweb.cgi/Owl/packages/glibc/crypt_blowfish/crypt_gensalt.c?only_with_tag=CRYPT_BLOWFISH_1_0 Source: CCN Type: RHSA-2006-0526 postgresql security update Source: CCN Type: SA18772 Openwall crypt_blowfish Salt Generation Weakness Source: SECUNIA Type: Patch, Vendor Advisory 18772 Source: SECUNIA Type: Vendor Advisory 20232 Source: CCN Type: SA20653 Avaya Products PostgreSQL Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory 20653 Source: SECUNIA Type: Vendor Advisory 20782 Source: CONFIRM Type: UNKNOWN http://support.avaya.com/elmodocs2/security/ASA-2006-113.htm Source: CCN Type: ASA-2006-113 postgresql security update (RHSA-2006-0526) Source: CCN Type: crypt_blowfish Web site Modern password hashing for your software and your servers Source: OSVDB Type: UNKNOWN 23005 Source: CCN Type: OSVDB ID: 23005 crypt_blowfish crypt_gensalt*() Functions Salt Generation Weakness Source: REDHAT Type: UNKNOWN RHSA-2006:0526 Source: BUGTRAQ Type: UNKNOWN 20060207 crypt_blowfish 1.0 Source: VUPEN Type: Vendor Advisory ADV-2006-0477 Source: XF Type: UNKNOWN cryptblowfish-salt-weak-password-hashes(24590) Source: XF Type: UNKNOWN cryptblowfish-salt-information-disclosure(24590) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:11502 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Denotes that component is vulnerable | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |