Back to search
CVE-2015-0886
Published: Feb 28, 2015
Modified: Aug 6, 2024
PUBLISHED
Description
Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
FEDORA-2015-3032
vendor-advisory
x_refsource_FEDORA
FEDORA-2015-3120
vendor-advisory
x_refsource_FEDORA
JVN#77718330
third-party-advisory
x_refsource_JVN
http://www.mindrot.org/projects/jBCrypt/news/rel04.html
x_refsource_CONFIRM
FEDORA-2015-2994
vendor-advisory
x_refsource_FEDORA
JVNDB-2015-000033
third-party-advisory
x_refsource_JVNDB
https://bugzilla.mindrot.org/show_bug.cgi?id=2097
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now