CVE Vulnerabilities

CVE-2008-1484

Published: Mar 24, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.5 LOW
AV:N/AC:M/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The password reset feature in PunBB 1.2.16 and earlier uses predictable random numbers based on the system time, which allows remote authenticated users to determine the new password via a brute force attack on a seed that is based on the approximate creation time of the targeted account. NOTE: this issue might be related to CVE-2006-5737.

Affected Software

NameVendorStart VersionEnd Version
PunbbPunbb1.0 (including)1.0 (including)
PunbbPunbb1.0.1 (including)1.0.1 (including)
PunbbPunbb1.0_alpha (including)1.0_alpha (including)
PunbbPunbb1.0_beta1 (including)1.0_beta1 (including)
PunbbPunbb1.0_beta2 (including)1.0_beta2 (including)
PunbbPunbb1.0_beta3 (including)1.0_beta3 (including)
PunbbPunbb1.0_rc1 (including)1.0_rc1 (including)
PunbbPunbb1.0_rc2 (including)1.0_rc2 (including)
PunbbPunbb1.1 (including)1.1 (including)
PunbbPunbb1.1.1 (including)1.1.1 (including)
PunbbPunbb1.1.2 (including)1.1.2 (including)
PunbbPunbb1.1.3 (including)1.1.3 (including)
PunbbPunbb1.1.4 (including)1.1.4 (including)
PunbbPunbb1.1.5 (including)1.1.5 (including)
PunbbPunbb1.2 (including)1.2 (including)
PunbbPunbb1.2.1 (including)1.2.1 (including)
PunbbPunbb1.2.2 (including)1.2.2 (including)
PunbbPunbb1.2.3 (including)1.2.3 (including)
PunbbPunbb1.2.4 (including)1.2.4 (including)
PunbbPunbb1.2.5 (including)1.2.5 (including)
PunbbPunbb1.2.6 (including)1.2.6 (including)
PunbbPunbb1.2.7 (including)1.2.7 (including)
PunbbPunbb1.2.8 (including)1.2.8 (including)
PunbbPunbb1.2.9 (including)1.2.9 (including)
PunbbPunbb1.2.10 (including)1.2.10 (including)
PunbbPunbb1.2.11 (including)1.2.11 (including)
PunbbPunbb1.2.12 (including)1.2.12 (including)
PunbbPunbb1.2.13 (including)1.2.13 (including)
PunbbPunbb1.2.14 (including)1.2.14 (including)
PunbbPunbb1.2.15 (including)1.2.15 (including)
PunbbPunbb1.2.16 (including)1.2.16 (including)

References