CVE Vulnerabilities

CVE-2001-1354

Published: Jul 20, 2001 | Modified: Dec 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to decrypt passwords or use a different password that has the same hash value as the correct password.

Affected Software

Name Vendor Start Version End Version
Dmail Netwin 2.5d (including) 2.5d (including)
Dmail Netwin 2.7 (including) 2.7 (including)
Dmail Netwin 2.7q (including) 2.7q (including)
Dmail Netwin 2.7r (including) 2.7r (including)
Dmail Netwin 2.8e (including) 2.8e (including)
Dmail Netwin 2.8f (including) 2.8f (including)
Dmail Netwin 2.8g (including) 2.8g (including)
Dmail Netwin 2.8h (including) 2.8h (including)
Dmail Netwin 2.8i (including) 2.8i (including)
Surgeftp Netwin 1.0b (including) 1.0b (including)
Surgeftp Netwin 2.0a (including) 2.0a (including)
Surgeftp Netwin 2.0b (including) 2.0b (including)

References