PT-2008-1550 · Lsrunase+1 · Lsrunase+1

Published

2008-02-05

·

Updated

2018-10-15

·

CVE-2007-6340

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions LSrunasE version 1.0 Supercrypt version 1.0
Description The issue makes it easier for local users to obtain cleartext passwords because the RC4 stream cipher is used without constructing a unique initialization vector (IV).
Recommendations For LSrunasE version 1.0, consider disabling the use of the RC4 stream cipher until a patch is available. For Supercrypt version 1.0, consider disabling the use of the RC4 stream cipher until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-6340

Affected Products

Lsrunase
Supercrypt