PT-2011-2011 · Best Practical Solutions · Rt

Published

2011-01-25

·

Updated

2023-02-13

·

CVE-2011-0009

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Best Practical Solutions RT versions 3.x through 3.8.9rc1 Best Practical Solutions RT versions 4.x through 4.0.0rc3
Description The issue makes it easier for attackers to determine cleartext passwords via a brute-force attack on the database, due to the use of the MD5 algorithm for password hashes.
Recommendations For versions 3.x through 3.8.9rc1, update to version 3.8.9rc2 or later. For versions 4.x through 4.0.0rc3, update to version 4.0.0rc4 or later.

Fix

Weakness Enumeration

Related Identifiers

CVE-2011-0009
DSA-2150-1

Affected Products

Rt