7.2
CVSSv2

CVE-2000-0250

Published: 14/04/2000 Updated: 10/09/2008
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The crypt function in QNX uses weak encryption, which allows local users to decrypt passwords.

Vulnerable Product Search on Vulmon Subscribe to Product

qnx qnx 4.25a

Exploits

/* source: wwwsecurityfocuscom/bid/1114/info A design error in the operation of the crypt(3) function exists in QNX, from QNX System Software, Limited (QSSL) The flaw allows the recovery of passwords from the hashes On most Unix variants, crypt(3) is based on a variant of the DES encryption algorithm, used as a hashing algorithm QNX, ...