PT-2008-1550 · Lsrunase+1 · Lsrunase+1
Publicado
2008-02-05
·
Atualizado
2018-10-15
·
CVE-2007-6340
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
LSrunasE version 1.0
Supercrypt version 1.0
Description
The issue makes it easier for local users to obtain cleartext passwords because the RC4 stream cipher is used without constructing a unique initialization vector (IV).
Recommendations
For LSrunasE version 1.0, consider disabling the use of the RC4 stream cipher until a patch is available.
For Supercrypt version 1.0, consider disabling the use of the RC4 stream cipher until a patch is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Lsrunase
Supercrypt