5
CVSSv2

CVE-2015-0886

Published: 28/02/2015 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt prior to 0.4 makes it easier for remote malicious users to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mindrot jbcrypt

fedoraproject fedora 22

fedoraproject fedora 20

fedoraproject fedora 21

Vendor Advisories

Debian Bug report logs - #780102 libjbcrypt-java: CVE-2015-0886 Package: libjbcrypt-java; Maintainer for libjbcrypt-java is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Source for libjbcrypt-java is src:libjbcrypt-java (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> D ...
Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 04 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent ...