Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9h6p-92jq-888x

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью

Описание

Integer Overflow or Wraparound in JBCrypt

Integer overflow in the crypt_raw method in the key-stretching implementation in JBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.

Пакеты

Наименование

org.mindrot:jbcrypt

maven
Затронутые версииВерсия исправления

< 0.4

0.4

EPSS

Процентиль: 85%
0.02478
Низкий

Дефекты

CWE-190

Связанные уязвимости

ubuntu
почти 11 лет назад

Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.

redhat
почти 11 лет назад

Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.

nvd
почти 11 лет назад

Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.

debian
почти 11 лет назад

Integer overflow in the crypt_raw method in the key-stretching impleme ...

EPSS

Процентиль: 85%
0.02478
Низкий

Дефекты

CWE-190