Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-1895

Опубликовано: 28 янв. 2020
Источник: debian
EPSS Низкий

Описание

The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to bypass authentication via multiple authentication requests, which trigger the password hash to be overwritten.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-bcryptfixed0.4-1package
python-bcryptnot-affectedsqueezepackage

Примечания

  • https://code.google.com/p/py-bcrypt/source/detail?r=b03cc5246ea21a839fd027da5616d8d470247558

EPSS

Процентиль: 86%
0.02835
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to bypass authentication via multiple authentication requests, which trigger the password hash to be overwritten.

CVSS3: 7.5
nvd
больше 6 лет назад

The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to bypass authentication via multiple authentication requests, which trigger the password hash to be overwritten.

CVSS3: 7.5
github
почти 5 лет назад

Improper Restriction of Excessive Authentication Attempts in py-bcrypt

EPSS

Процентиль: 86%
0.02835
Низкий