Vulnerability CVE-2008-3188


Published: 2008-07-22   Modified: 2012-02-12

Description:
libxcrypt in SUSE openSUSE 11.0 uses the DES algorithm when the configuration specifies the MD5 algorithm, which makes it easier for attackers to conduct brute-force attacks against hashed passwords.

Type:

CWE-310

(Cryptographic Issues)

CVSS2 => (AV:L/AC:H/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.2/10
10/10
1.9/10
Exploit range
Attack complexity
Authentication
Local
High
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Opensuse -> Libxcrypt 

 References:
http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00008.html
http://xforce.iss.net/xforce/xfdb/43927
http://www.securityfocus.com/bid/30301
http://secunia.com/advisories/31339
http://secunia.com/advisories/31096
http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00001.html

Copyright 2024, cxsecurity.com

 

Back to Top