VulnerabilityModified
CVE-2011-0009
Best Practical Solutions RT 3.x before 3.8.9rc2 and 4.x before 4.0.0rc4 uses the MD5 algorithm for password hashes, which makes it easier for context-dependent attackers to determine cleartext passwords via a brute-force attack on the database.
MEDIUM 4.3EPSS 1.88%
Does this matter?
Lower severity and a low EPSS score (1.88%). Track it; it rarely justifies an emergency change on its own.
Description
Best Practical Solutions RT 3.x before 3.8.9rc2 and 4.x before 4.0.0rc4 uses the MD5 algorithm for password hashes, which makes it easier for context-dependent attackers to determine cleartext passwords via a brute-force attack on the database.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 1.88% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- bestpractical/rt
- Source
- secalert@redhat.com
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=610850Patch
- http://lists.bestpractical.com/pipermail/rt-announce/2011-January/000185.htmlPatch
- http://lists.fedoraproject.org/pipermail/package-announce/2011-March/054740.html
- http://osvdb.org/70661
- http://secunia.com/advisories/43438Vendor Advisory
- http://www.debian.org/security/2011/dsa-2150
- http://www.securityfocus.com/bid/45959
- http://www.vupen.com/english/advisories/2011/0190Vendor Advisory
- http://www.vupen.com/english/advisories/2011/0475Vendor Advisory
- http://www.vupen.com/english/advisories/2011/0576Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=672250Patch
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=610850Patch
- http://lists.bestpractical.com/pipermail/rt-announce/2011-January/000185.htmlPatch
- http://lists.fedoraproject.org/pipermail/package-announce/2011-March/054740.html
- http://osvdb.org/70661
- http://secunia.com/advisories/43438Vendor Advisory
- http://www.debian.org/security/2011/dsa-2150
- http://www.securityfocus.com/bid/45959
- http://www.vupen.com/english/advisories/2011/0190Vendor Advisory
- http://www.vupen.com/english/advisories/2011/0475Vendor Advisory
- http://www.vupen.com/english/advisories/2011/0576Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=672250Patch
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.