LSrunase and Supercrypt RC4 Weak Encryption Vulnerability
BID:27500
Info
LSrunase and Supercrypt RC4 Weak Encryption Vulnerability
| Bugtraq ID: | 27500 |
| Class: | Design Error |
| CVE: |
CVE-2008-0580 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 29 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | Daniel Roethlisberger is credited with the discovery of this vulnerability. |
| Vulnerable: |
Moernaut Supercrypt 1.0 Moernaut LSrunasE 1.0 |
| Not Vulnerable: |
Moernaut Supercrypt 2.0 Moernaut LSrunasE 2.0 |
Discussion
LSrunase and Supercrypt RC4 Weak Encryption Vulnerability
LSrunase and Supercrypt are prone to a weak-encryption vulnerability because the software uses the RC4 algorithm to encrypt sensitive information in an insecure manner.
Attackers can exploit this issue to obtain sensitive information such as user-authentication credentials. Information obtained will lead to other attacks.
This issue affects LSrunase 1.0 and Supercrypt 1.0; prior versions may also be affected.
LSrunase and Supercrypt are prone to a weak-encryption vulnerability because the software uses the RC4 algorithm to encrypt sensitive information in an insecure manner.
Attackers can exploit this issue to obtain sensitive information such as user-authentication credentials. Information obtained will lead to other attacks.
This issue affects LSrunase 1.0 and Supercrypt 1.0; prior versions may also be affected.
Exploit / POC
LSrunase and Supercrypt RC4 Weak Encryption Vulnerability
Attackers can exploit this issue by using readily available network utilities.
Attackers can exploit this issue by using readily available network utilities.
Solution / Fix
LSrunase and Supercrypt RC4 Weak Encryption Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Solution:
The vendor released an update to address this issue. Please see the references for more information.