PT-2006-2387 · Passwordsafe · Passwordsafe
Published
2006-03-24
·
Updated
2018-10-18
·
CVE-2006-1378
CVSS v2.0
4.9
Medium
| Vector | AV:L/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PasswordSafe version 3.0 beta
Description
The issue concerns the use of a weak random number generator, specifically the C++
rand function, during the generation of the database encryption key. This weakness makes it easier for attackers to decrypt the database and steal passwords by generating keys for all possible rand() seed values and conducting a known plaintext attack.Recommendations
For PasswordSafe version 3.0 beta, consider using an alternative, more secure random number generator to mitigate the risk of decryption by attackers. As a temporary workaround, restrict access to sensitive data stored in the database until a more secure version is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Passwordsafe