Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

openSUSE 'libxcrypt' Insecure Password Hash Weakness

openSUSE is prone to an insecure password-hash weakness.

This issue stems from a design error when 'libxcrypt' is used to calculate password hashes. This weakness can result in the creation of weak passwords and can lead to a false sense of security.

Note that the default installation of openSUSE uses 'blowfish', which isn't affected by the hash issue.







 

Privacy Statement
Copyright 2009, SecurityFocus