Macromedia Contribute Publishing Server Insecure Shared Connection Key Encryption Weakness
BID:15438
Info
Macromedia Contribute Publishing Server Insecure Shared Connection Key Encryption Weakness
| Bugtraq ID: | 15438 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 15 2005 12:00AM |
| Updated: | Nov 15 2005 12:00AM |
| Credit: | Chris Dary reported this issue to the vendor. |
| Vulnerable: |
Macromedia Contribute Publishing Server 1.0 1 Macromedia Contribute Publishing Server 1.0 Macromedia Contribute Publishing Server |
| Not Vulnerable: |
Macromedia Contribute Publishing Server 1.11 |
Discussion
Macromedia Contribute Publishing Server Insecure Shared Connection Key Encryption Weakness
Macromedia CPS (Contribute Publishing Server) is susceptible to an insecure shared connection key encryption weakness. These shared connection keys are used in shared FTP login credentials.
This issue may allow remote attackers to decrypt the contents of network packets, gaining access to the cleartext contents of authentication credentials, aiding them in further attacks.
Versions prior to 1.11 of Macromedia CPS are susceptible to this issue.
Macromedia CPS (Contribute Publishing Server) is susceptible to an insecure shared connection key encryption weakness. These shared connection keys are used in shared FTP login credentials.
This issue may allow remote attackers to decrypt the contents of network packets, gaining access to the cleartext contents of authentication credentials, aiding them in further attacks.
Versions prior to 1.11 of Macromedia CPS are susceptible to this issue.
Exploit / POC
Macromedia Contribute Publishing Server Insecure Shared Connection Key Encryption Weakness
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Macromedia Contribute Publishing Server Insecure Shared Connection Key Encryption Weakness
Solution:
The vendor has released advisory MPSB05-08, along with version 1.11 of the affected software to address this issue. Please see the referenced advisory for further information on obtaining fixes.
Solution:
The vendor has released advisory MPSB05-08, along with version 1.11 of the affected software to address this issue. Please see the referenced advisory for further information on obtaining fixes.
References
Macromedia Contribute Publishing Server Insecure Shared Connection Key Encryption Weakness
References:
References:
- Contribute Publishing Server Product Page (Macromedia)
- MPSB05-08 Contribute Publishing Server Password Encryption (Macromedia)