CryptoBuddy Predictable Encrypted Passphrase Weakness
BID:6810
Info
CryptoBuddy Predictable Encrypted Passphrase Weakness
| Bugtraq ID: | 6810 |
| Class: | Design Error |
| CVE: |
CVE-2003-1391 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 10 2003 12:00AM |
| Updated: | Jul 06 2016 02:06PM |
| Credit: | The discovery of this vulnerability has been credited to [email protected]. |
| Vulnerable: |
Research Triangle Software CryptoBuddy 1.2.2 Research Triangle Software CryptoBuddy 1.2 Research Triangle Software CryptoBuddy 1.0 Research Triangle Software CryptoBuddy 1.0 |
| Not Vulnerable: | |
Discussion
CryptoBuddy Predictable Encrypted Passphrase Weakness
It has been reported that the passphrase encryption algorithm employed by CryptoBuddy is weak. Specifically, the encryption algorithm used generates predictable ciphertext for specific sequences of characters used as a passphrase.
An attacker can exploit this weakness to build a dictionary of encrypted passphrases and use this to decrypt stolen files.
It has been reported that the passphrase encryption algorithm employed by CryptoBuddy is weak. Specifically, the encryption algorithm used generates predictable ciphertext for specific sequences of characters used as a passphrase.
An attacker can exploit this weakness to build a dictionary of encrypted passphrases and use this to decrypt stolen files.
Solution / Fix
CryptoBuddy Predictable Encrypted Passphrase Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.