Computer Security
[EN] securityvulns.ru
no-pyccku



PostgreSQL weak cryptography
Published:21.04.2005
Source:BUGTRAQ
SecurityVulns ID:4719
Type:remote
Level:5/10
Description:Username is used as a salt for MD5-hashed passwords. In addition, during authentication hash may be used directly without knowledge of cleartext password.
Affected:POSTGRESQL : PostgreSQL 7.4
Original documentdocumentStephen Frost, Postgres: pg_hba.conf, md5, pg_shadow, encrypted passwords (21.04.2005)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru