PT-2008-1550 · Lsrunase+1 · Lsrunase+1
Published
2008-02-05
·
Updated
2018-10-15
·
CVE-2007-6340
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
LSrunasE version 1.0
Supercrypt version 1.0
Description
The issue makes it easier for local users to obtain cleartext passwords because the RC4 stream cipher is used without constructing a unique initialization vector (IV).
Recommendations
For LSrunasE version 1.0, consider disabling the use of the RC4 stream cipher until a patch is available.
For Supercrypt version 1.0, consider disabling the use of the RC4 stream cipher until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lsrunase
Supercrypt