CVE

Id
4158  
CVE No.
CVE-2001-1354  
Status
Candidate  
Description
NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to decrypt passwords or use a different password that has the same hash value as the correct password.  
Phase
Proposed (20020611)  
Votes
ACCEPT(3) Alderson, Cole, Frech | NOOP(4) Cox, Foat, Green, Wall  
Comments