PT-2015-4942 · Owasp+1 · Bcrypt+1
Marcus Rathsfeld
·
Published
2015-02-28
·
Updated
2026-05-18
·
CVE-2015-0886
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
jBCrypt versions prior to 0.4
Description
The issue is related to an integer overflow in the
crypt raw method within the key-stretching implementation. This makes it easier for remote attackers to determine the cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.Recommendations
For versions prior to 0.4, update to version 0.4 or later to resolve the issue. As a temporary workaround, consider restricting access to password hashes to minimize the risk of exploitation.
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Bcrypt