1.2
CVSSv2

CVE-2006-0591

Published: 08/02/2006 Updated: 19/10/2018
CVSS v2 Base Score: 1.2 | Impact Score: 2.9 | Exploitability Score: 1.9
VMScore: 107
Vector: AV:L/AC:H/Au:N/C:P/I:N/A:N

Vulnerability Summary

The crypt_gensalt functions for BSDI-style extended DES-based and FreeBSD-sytle MD5-based password hashes in crypt_blowfish 0.4.7 and previous versions do not evenly and randomly distribute salts, which makes it easier for malicious users to guess passwords from a stolen password file due to the increased number of collisions.

Vulnerable Product Search on Vulmon Subscribe to Product

solar designer crypt blowfish 0.4.7