PT-2015-4942 · Owasp+1 · Bcrypt+1

Marcus Rathsfeld

·

Published

2015-02-28

·

Updated

2026-05-18

·

CVE-2015-0886

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions jBCrypt versions prior to 0.4
Description The issue is related to an integer overflow in the crypt raw method within the key-stretching implementation. This makes it easier for remote attackers to determine the cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.
Recommendations For versions prior to 0.4, update to version 0.4 or later to resolve the issue. As a temporary workaround, consider restricting access to password hashes to minimize the risk of exploitation.

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1073
CLEANSTART-2026-GH89210
CVE-2015-0886
GHSA-9H6P-92JQ-888X

Affected Products

Alt Linux
Bcrypt