Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-20013

Опубликовано: 19 фев. 2022
Источник: debian
EPSS Низкий

Описание

sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password.

Примечания

  • https://akkadia.org/drepper/SHA-crypt.txt

  • https://pthree.org/2018/05/23/do-not-use-sha256crypt-sha512crypt-theyre-dangerous/

  • https://twitter.com/solardiz/status/795601240151457793

  • Inherent algorithmic flaw, applications can set password limits or instead use a

  • different hashing algorithm

EPSS

Процентиль: 53%
0.00307
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 4 года назад

sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password.

CVSS3: 7.5
nvd
почти 4 года назад

sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password.

github
почти 4 года назад

sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password.

EPSS

Процентиль: 53%
0.00307
Низкий