Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-1895

Опубликовано: 28 янв. 2020
Источник: debian
EPSS Низкий

Описание

The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to bypass authentication via multiple authentication requests, which trigger the password hash to be overwritten.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-bcryptfixed0.4-1package
python-bcryptnot-affectedsqueezepackage

Примечания

  • https://code.google.com/p/py-bcrypt/source/detail?r=b03cc5246ea21a839fd027da5616d8d470247558

EPSS

Процентиль: 51%
0.00279
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to bypass authentication via multiple authentication requests, which trigger the password hash to be overwritten.

CVSS3: 7.5
nvd
около 6 лет назад

The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to bypass authentication via multiple authentication requests, which trigger the password hash to be overwritten.

CVSS3: 7.5
github
больше 4 лет назад

Improper Restriction of Excessive Authentication Attempts in py-bcrypt

EPSS

Процентиль: 51%
0.00279
Низкий