Best Practical Solutions RT 3.x before 3.8.9rc2 and 4.x before 4.0.0rc4 uses the MD5 algorithm for password hashes, which makes it easier for context-dependent attackers to determine cleartext passwords via a brute-force attack on the database.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
21 Nov 2024, 01:23
Type | Values Removed | Values Added |
---|---|---|
References | () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=610850 - Patch | |
References | () http://lists.bestpractical.com/pipermail/rt-announce/2011-January/000185.html - Patch | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2011-March/054740.html - | |
References | () http://osvdb.org/70661 - | |
References | () http://secunia.com/advisories/43438 - Vendor Advisory | |
References | () http://www.debian.org/security/2011/dsa-2150 - | |
References | () http://www.securityfocus.com/bid/45959 - | |
References | () http://www.vupen.com/english/advisories/2011/0190 - Vendor Advisory | |
References | () http://www.vupen.com/english/advisories/2011/0475 - Vendor Advisory | |
References | () http://www.vupen.com/english/advisories/2011/0576 - Vendor Advisory | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=672250 - Patch | |
References | () https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E - |
Information
Published : 2011-01-25 19:00
Updated : 2024-11-21 01:23
NVD link : CVE-2011-0009
Mitre link : CVE-2011-0009
CVE.ORG link : CVE-2011-0009
JSON object : View
Products Affected
bestpractical
- rt
CWE
CWE-310
Cryptographic Issues