Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.
References
Configurations
History
No history.
Information
Published : 2015-02-28 02:59
Updated : 2023-11-07 02:23
NVD link : CVE-2015-0886
Mitre link : CVE-2015-0886
CVE.ORG link : CVE-2015-0886
JSON object : View
Products Affected
mindrot
- jbcrypt
fedoraproject
- fedora
CWE
CWE-190
Integer Overflow or Wraparound