CVE-2016-2379
Summary
| CVE | CVE-2016-2379 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-03-29 20:59:00 UTC |
| Updated | 2017-04-10 22:16:00 UTC |
| Description | The Mxit protocol uses weak encryption when encrypting user passwords, which might allow attackers to (1) decrypt hashed passwords by leveraging knowledge of client registration codes or (2) gain login access by eavesdropping on login messages and re-using the hashed passwords. |
Risk And Classification
Problem Types: CWE-326
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Talos Website | MISC | www.talosintelligence.com | Third Party Advisory |
| Pidgin: Multiple vulnerabilities (GLSA 201701-38) — Gentoo Security | GENTOO | security.gentoo.org | Third Party Advisory |
| Pidgin Multiple Security Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Pidgin Security Advisories | CONFIRM | pidgin.im | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710343 Gentoo Linux Pidgin Multiple Vulnerabilities (GLSA 201701-38)