CVE
- Id
- 3410
- CVE No.
- CVE-2001-0597
- Status
- Candidate
- Description
- Zetetic Secure Tool for Recalling Important Passwords (STRIP) 0.5 and earlier for the PalmOS allows a local attacker to recover passwords via a brute force attack. This attack is made feasible by STRIP"s use of SysRandom, which is seeded by TimeGetTicks, and an implementation flaw which vastly reduces the password "search space".
- Phase
- Proposed (20010727)
- Votes
- ACCEPT(3) Cole, Frech, Ziese | NOOP(2) Foat, Wall | REVIEWING(1) Bishop
- Comments
- Frech> CONFIRM:http://www.zetetic.net/docs/bugs/security_04-09-2001. | html