Lucene search

K
ubuntucveUbuntu.comUB:CVE-2017-7252
HistoryNov 03, 2023 - 12:00 a.m.

CVE-2017-7252

2023-11-0300:00:00
ubuntu.com
ubuntu.com
11
cve-2017-7252
botan library
bcrypt hashing
password brute force

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

6.6

Confidence

Low

EPSS

0.001

Percentile

37.2%

bcrypt password hashing in Botan before 2.1.0 does not correctly handle
passwords with a length between 57 and 72 characters, which makes it easier
for attackers to determine the cleartext password.

Notes

Author Note
sbeattie introduced in 1.11.0

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

6.6

Confidence

Low

EPSS

0.001

Percentile

37.2%