FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2011-0009

This CVE name corresponds to:

Entered Topic
2012-05-23 RT -- Multiple Vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2011-0009
Phase Assigned(20101207)

Description

Best Practical Solutions RT 3.x before 3.8.9rc2 and 4.x before 4.0.0rc4 uses the MD5 algorithm for password hashes, which makes it easier for context-dependent attackers to determine cleartext passwords via a brute-force attack on the database.

References

Source Reference
MLIST [rt-announce] 20110119 Security vulnerability in RT 3.0 and up
CONFIRM http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=610850
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=672250
DEBIAN DSA-2150
FEDORA FEDORA-2011-1677
BID 45959
OSVDB 70661
SECUNIA 43438
VUPEN ADV-2011-0190
VUPEN ADV-2011-0475
VUPEN ADV-2011-0576