Title : Openwall crypt_blowfish Password Hash Generation Security Weakness VUPEN ID : VUPEN/ADV-2006-0477 CVE ID : GENERIC-MAP-NOMATCH
Rated as : Low Risk
Remotely Exploitable : No Release Date : 2006-02-08
Technical Description
A security weakness has been identified in Openwall crypt_blowfish, which could be exploited by attackers to bypass security restrictions. This issue is due to an error in the "crypt_gensalt" functions for BSDI-style extended DES-based and FreeBSD-sytle MD5-based password hashes that do not evenly and randomly distribute salts, which makes it easier for attackers to guess passwords from a stolen password file due to the increased number of collisions.