Back to search
CVE-2002-1657
Published: Apr 22, 2005
Modified: Jan 16, 2025
PUBLISHED
Description
PostgreSQL uses the username for a salt when generating passwords, which makes it easier for remote attackers to guess passwords via a brute force attack.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
postgresql-md5-salt-weak-security(20215)
vdb-entry
x_refsource_XF
20050420 Postgres: pg_hba.conf, md5, pg_shadow, encrypted passwords
mailing-list
x_refsource_BUGTRAQ
20050420 Re: Postgres: pg_hba.conf, md5, pg_shadow, encrypted passwords
mailing-list
x_refsource_BUGTRAQ
[pgsql-admin] 20020821 Re: OT: password encryption (salt theory)
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now