5
CVSSv2

CVE-2008-6792

Published: 07/05/2009 Updated: 17/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

system-tools-backends prior to 2.6.0-1ubuntu1.1 in Ubuntu 8.10, as used by "Users and Groups" in GNOME System Tools, hashes account passwords with 3DES and consequently limits effective password lengths to eight characters, which makes it easier for context-dependent malicious users to successfully conduct brute-force password attacks.

Vulnerable Product Search on Vulmon Subscribe to Product

ubuntu linux 8.10

Vendor Advisories

Debian Bug report logs - #527952 system-tools-backends: CVE-2008-6792 limiting effective password length to 8 characters Package: system-tools-backends; Maintainer for system-tools-backends is Andriy Grytsenko <andrej@repkievua>; Source for system-tools-backends is src:system-tools-backends (PTS, buildd, popcon) Reported b ...