BusyBox Insecure Password Hash Weakness

BusyBox is prone to an insecure password-hash weakness. This issue is due to a design flaw that results in password hashes being created in an insecure manner.

This issue allows attackers to use precomputed password hashes in brute-force attacks if they can gain access to password hashes by some means (such as exploiting another vulnerability).


 

Privacy Statement
Copyright 2010, SecurityFocus