CVE
- Id
- 3772
- CVE No.
- CVE-2001-0967
- Status
- Candidate
- Description
- Knox Arkeia server 4.2, and possibly other versions, uses a constant salt when encrypting passwords using the crypt() function, which makes it easier for an attacker to conduct brute force password guessing.
- Phase
- Proposed (20020131)
- Votes
- ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall
- Comments
- Frech> XF:arkeia-weak-password-encryption(7000)