Security Advisory

CVE-2015-0886

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2015-02-28 02:00:00
Last updated 2024-08-06 04:26:11
Assigner jpcert
CVSS score not scored
State PUBLISHED

Description

Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.