Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-0591

Опубликовано: 08 фев. 2006
Источник: nvd
CVSS2: 1.2
EPSS Низкий

Описание

The crypt_gensalt functions for BSDI-style extended DES-based and FreeBSD-sytle MD5-based password hashes in crypt_blowfish 0.4.7 and earlier do not evenly and randomly distribute salts, which makes it easier for attackers to guess passwords from a stolen password file due to the increased number of collisions.

Комментарий

This vulnerability may only be exploited in conjunction with another vulnerability. The password file (normally shadowed) must first be stolen.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:solar_designer:crypt_blowfish:0.4.7:*:*:*:*:*:*:*

EPSS

Процентиль: 27%
0.00091
Низкий

1.2 Low

CVSS2

Дефекты

CWE-310

Связанные уязвимости

redhat
больше 19 лет назад

The crypt_gensalt functions for BSDI-style extended DES-based and FreeBSD-sytle MD5-based password hashes in crypt_blowfish 0.4.7 and earlier do not evenly and randomly distribute salts, which makes it easier for attackers to guess passwords from a stolen password file due to the increased number of collisions.

github
больше 3 лет назад

The crypt_gensalt functions for BSDI-style extended DES-based and FreeBSD-sytle MD5-based password hashes in crypt_blowfish 0.4.7 and earlier do not evenly and randomly distribute salts, which makes it easier for attackers to guess passwords from a stolen password file due to the increased number of collisions.

EPSS

Процентиль: 27%
0.00091
Низкий

1.2 Low

CVSS2

Дефекты

CWE-310