IBM Lotus Domino Password Encryption Weakness
BID:14389
Info
IBM Lotus Domino Password Encryption Weakness
| Bugtraq ID: | 14389 |
| Class: | Design Error |
| CVE: |
CVE-2005-2428 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jul 26 2005 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | Discovery is credited to Leandro Meiners <[email protected]>. |
| Vulnerable: |
IBM Lotus Domino Enterprise Server 6.5.4 IBM Lotus Domino Enterprise Server 6.5.2 IBM Lotus Domino Enterprise Server 6.0.5 IBM Lotus Domino Enterprise Server 6.0.1 IBM Lotus Domino Enterprise Server 5.0.13 IBM Lotus Domino Enterprise Server 5.0.12 IBM Lotus Domino Enterprise Server 5.0.9 IBM Lotus Domino Enterprise Server 5.0.3 IBM Lotus Domino 6.5.4 IBM Lotus Domino 6.5.3 IBM Lotus Domino 6.5.2 IBM Lotus Domino 6.5.1 IBM Lotus Domino 6.5 .0 IBM Lotus Domino 6.0.5 IBM Lotus Domino 6.0.4 IBM Lotus Domino 6.0.4 IBM Lotus Domino 6.0.3 IBM Lotus Domino 6.0.2 CF2 IBM Lotus Domino 6.0.2 IBM Lotus Domino 6.0.1 IBM Lotus Domino 6.0 IBM Lotus Domino 5.0.13 |
| Not Vulnerable: | |
Discussion
IBM Lotus Domino Password Encryption Weakness
IBM Lotus Domino is affected by a password encryption weakness. This issue arises due to a design error.
Reportedly, the algorithm used by Lotus Domino to encrypt user passwords does not use a salt value.
This can aid in brute force attacks by significantly reducing the time needed to crack a password. Attackers may also pre-compute password hashes before targeting a vulnerable computer.
All versions of Lotus Domino are considered to be affected by this weakness.
IBM Lotus Domino is affected by a password encryption weakness. This issue arises due to a design error.
Reportedly, the algorithm used by Lotus Domino to encrypt user passwords does not use a salt value.
This can aid in brute force attacks by significantly reducing the time needed to crack a password. Attackers may also pre-compute password hashes before targeting a vulnerable computer.
All versions of Lotus Domino are considered to be affected by this weakness.
Exploit / POC
IBM Lotus Domino Password Encryption Weakness
An exploit is not required.
An exploit is not required.
Solution / Fix
IBM Lotus Domino Password Encryption Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
IBM Lotus Domino Password Encryption Weakness
References:
References: