eCryptfs Insecure Password Generation Weakness
BID:72560
Info
eCryptfs Insecure Password Generation Weakness
| Bugtraq ID: | 72560 |
| Class: | Design Error |
| CVE: |
CVE-2014-9687 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 10 2015 12:00AM |
| Updated: | Mar 19 2015 08:05AM |
| Credit: | Martin Steigerwald |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 eCryptfs eCryptfs 0 |
| Not Vulnerable: | |
Discussion
eCryptfs Insecure Password Generation Weakness
eCryptfs is prone to an insecure password generation weakness.
Successful exploits will allow remote attackers to perform brute-force attacks and obtain passwords. This may aid in further attacks.
eCryptfs is prone to an insecure password generation weakness.
Successful exploits will allow remote attackers to perform brute-force attacks and obtain passwords. This may aid in further attacks.
Exploit / POC
eCryptfs Insecure Password Generation Weakness
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
eCryptfs Insecure Password Generation Weakness
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
eCryptfs Insecure Password Generation Weakness
References:
References: