MEDIUM
The vulnerable-passwords script in Best Practical Solutions RT 3.x before 3.8.12 and 4.x before 4.0.6 does not update the password-hash algorithm for disabled user accounts, which makes it easier for context-dependent attackers to determine cleartext passwords, and possibly use these passwords after accounts are re-enabled, via a brute-force attack on the database
Published Jun 4, 2012
5.0
MEDIUMCVSS 2.0
EPSS 1.19%
Description
The vulnerable-passwords script in Best Practical Solutions RT 3.x before 3.8.12 and 4.x before 4.0.6 does not update the password-hash algorithm for disabled user accounts, which makes it easier for context-dependent attackers to determine cleartext passwords, and possibly use these passwords after accounts are re-enabled, via a brute-force attack on the database. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-0009.
Affected products
No data.
Configuration 1
OR
- 3.0.0
- 3.0.1
- 3.0.2
- 3.0.3
- 3.0.4
- 3.0.5
- 3.0.6
- 3.0.7
- 3.0.7.1
- 3.0.8
- 3.0.9
- 3.0.10
- 3.0.10
- 3.0.10
- 3.0.10
- 3.0.11
- 3.0.11
- 3.0.11
- 3.0.11
- 3.0.12
- 3.1.2
- 3.1.3
- 3.1.4
- 3.1.5
- 3.1.6
- 3.1.7
- 3.1.8
- 3.1.10
- 3.1.11
- 3.1.12
- 3.1.13
- 3.1.14
- 3.1.15
- 3.1.16
- 3.1.17
- 3.2.0
- 3.2.0
- 3.2.0
- 3.2.0
- 3.2.0
- 3.2.1
- 3.2.1
- 3.2.1
- 3.2.1
- 3.2.1
- 3.2.2
- 3.2.2
- 3.2.3
- 3.2.3
- 3.2.3
- 3.4.0
- 3.4.0
- 3.4.0
- 3.4.0
- 3.4.0
- 3.4.0
- 3.4.0
- 3.4.1
- 3.4.2
- 3.4.2
- 3.4.2
- 3.4.3
- 3.4.3
- 3.4.3
- 3.4.4
- 3.4.4
- 3.4.4
- 3.4.4
- 3.4.5
- 3.4.5
- 3.4.5
- 3.4.5
- 3.4.6
- 3.4.6
- 3.4.6
- 3.4.7
- 3.5.1
- 3.5.2
- 3.5.3
- 3.5.4
- 3.5.5
- 3.5.6
- 3.5.7
- 3.6.0
- 3.6.0
- 3.6.0
- 3.6.0
- 3.6.0
- 3.6.0
- 3.6.1
- 3.6.1
- 3.6.1
- 3.6.1
- 3.6.2
- 3.6.2
- 3.6.2
- 3.6.2
- 3.6.2
- 3.6.3
- 3.6.3
- 3.6.3
- 3.6.3
- 3.6.3
- 3.6.4
- 3.6.4
- 3.6.4
- 3.6.5
- 3.6.5
- 3.6.5
- 3.6.6
- 3.6.6
- 3.6.6
- 3.6.6
- 3.6.7
- 3.6.8
- 3.6.9
- 3.6.10
- 3.7.1
- 3.7.5
- 3.7.80
- 3.7.85
- 3.7.86
- 3.8.0
- 3.8.0
- 3.8.0
- 3.8.0
- 3.8.1
- 3.8.1
- 3.8.1
- 3.8.1
- 3.8.1
- 3.8.1
- 3.8.2
- 3.8.2
- 3.8.2
- 3.8.3
- 3.8.3
- 3.8.3
- 3.8.4
- 3.8.4
- 3.8.5
- 3.8.6
- 3.8.6
- 3.8.7
- 3.8.7
- 3.8.8
- 3.8.8
- 3.8.8
- 3.8.8
- 3.8.9
- 3.8.9
- 3.8.9
- 3.8.9
- 3.8.10
- 3.8.11
Configuration 2
OR
- 3.8.12
- 4.0.0
- 4.0.0
- 4.0.0
- 4.0.0
- 4.0.0
- 4.0.0
- 4.0.0
- 4.0.0
- 4.0.0
- 4.0.1
- 4.0.2
- 4.0.3
- 4.0.4
- 4.0.5
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- http://lists.bestpractical.com/pipermail/rt-announce/2012-May/000202.html mailing-listx_refsource_MLIST
- http://lists.bestpractical.com/pipermail/rt-announce/2012-May/000203.html mailing-listx_refsource_MLISTPatch
- http://lists.bestpractical.com/pipermail/rt-announce/2012-May/000204.html mailing-listx_refsource_MLISTPatch
- http://secunia.com/advisories/49259 third-party-advisoryx_refsource_SECUNIA
- http://www.securityfocus.com/bid/53660 vdb-entryx_refsource_BID
| Link | Providers | Tags |
|---|---|---|
| http://lists.bestpractical.com/pipermail/rt-announce/2012-May/000202.html | mailing-listx_refsource_MLIST | |
| http://lists.bestpractical.com/pipermail/rt-announce/2012-May/000203.html | mailing-listx_refsource_MLISTPatch | |
| http://lists.bestpractical.com/pipermail/rt-announce/2012-May/000204.html | mailing-listx_refsource_MLISTPatch | |
| http://secunia.com/advisories/49259 | third-party-advisoryx_refsource_SECUNIA | |
| http://www.securityfocus.com/bid/53660 | vdb-entryx_refsource_BID |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 4, 2012
Updated Aug 6, 2024
Reserved May 13, 2011
Link CVE-2011-2082
CISA Vulnrichment
Updated n/a