PT-2011-2011 · Best Practical Solutions · Rt
Published
2011-01-25
·
Updated
2023-02-13
·
CVE-2011-0009
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Best Practical Solutions RT versions 3.x through 3.8.9rc1
Best Practical Solutions RT versions 4.x through 4.0.0rc3
Description
The issue makes it easier for attackers to determine cleartext passwords via a brute-force attack on the database, due to the use of the MD5 algorithm for password hashes.
Recommendations
For versions 3.x through 3.8.9rc1, update to version 3.8.9rc2 or later.
For versions 4.x through 4.0.0rc3, update to version 4.0.0rc4 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rt