PT-2000-1431 · Passwd · Passwd

Publicado

2000-06-04

·

Atualizado

2008-09-10

·

CVE-2000-0492

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions PassWD version 1.2
Description The issue concerns the use of weak encryption, specifically trivial encoding, to store passwords. This allows an attacker with read access to the password file to easily decrypt the passwords.
Recommendations For PassWD version 1.2, consider updating the password storage mechanism to use a secure encryption method to protect passwords. As a temporary workaround, restrict access to the password file to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2000-0492

Produtos afetados

Passwd