2.1
CVSSv2

CVE-2006-1058

Published: 04/04/2006 Updated: 09/02/2024
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.

Vulnerable Product Search on Vulmon Subscribe to Product

busybox busybox 1.1.1

avaya message networking

avaya aura sip enablement services

avaya aura application enablement services 4.01

avaya aura application enablement services 4.1

avaya messaging storage server

Vendor Advisories

Debian Bug report logs - #360578 busybox: passwd uses null salt (weak encryption) [CVE-2006-1058] Package: busybox; Maintainer for busybox is Debian Install System Team <debian-boot@listsdebianorg>; Source for busybox is src:busybox (PTS, buildd, popcon) Reported by: Martin Pitt <martinpitt@ubuntucom> Date: Mon, ...