Vulnerabilities > CVE-2001-1467 - Unspecified vulnerability in DON Libes Expect 5.2.8
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
mkpasswd in expect 5.2.8, as used by Red Hat Linux 6.2 through 7.0, seeds its random number generator with its process ID, which limits the space of possible seeds and makes it easier for attackers to conduct brute force password attacks.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- http://archives.neohapsis.com/archives/bugtraq/2001-04/0173.html
- http://archives.neohapsis.com/archives/bugtraq/2001-04/0192.html
- http://securitytracker.com/id?1001303
- http://www.kb.cert.org/vuls/id/527736
- http://www.securityfocus.com/bid/2632
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6382