NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to decrypt passwords or use a different password that has the same hash value as the correct password.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Dmail | Netwin | 2.5d (including) | 2.5d (including) |
Dmail | Netwin | 2.7 (including) | 2.7 (including) |
Dmail | Netwin | 2.7q (including) | 2.7q (including) |
Dmail | Netwin | 2.7r (including) | 2.7r (including) |
Dmail | Netwin | 2.8e (including) | 2.8e (including) |
Dmail | Netwin | 2.8f (including) | 2.8f (including) |
Dmail | Netwin | 2.8g (including) | 2.8g (including) |
Dmail | Netwin | 2.8h (including) | 2.8h (including) |
Dmail | Netwin | 2.8i (including) | 2.8i (including) |
Surgeftp | Netwin | 1.0b (including) | 1.0b (including) |
Surgeftp | Netwin | 2.0a (including) | 2.0a (including) |
Surgeftp | Netwin | 2.0b (including) | 2.0b (including) |