CVE Vulnerabilities

CVE-2008-1484

Published: Mar 24, 2008 | Modified: Oct 11, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.5 LOW
AV:N/AC:M/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The password reset feature in PunBB 1.2.16 and earlier uses predictable random numbers based on the system time, which allows remote authenticated users to determine the new password via a brute force attack on a seed that is based on the approximate creation time of the targeted account. NOTE: this issue might be related to CVE-2006-5737.

Affected Software

Name Vendor Start Version End Version
Punbb Punbb 1.0 (including) 1.0 (including)
Punbb Punbb 1.0.1 (including) 1.0.1 (including)
Punbb Punbb 1.0_alpha (including) 1.0_alpha (including)
Punbb Punbb 1.0_beta1 (including) 1.0_beta1 (including)
Punbb Punbb 1.0_beta2 (including) 1.0_beta2 (including)
Punbb Punbb 1.0_beta3 (including) 1.0_beta3 (including)
Punbb Punbb 1.0_rc1 (including) 1.0_rc1 (including)
Punbb Punbb 1.0_rc2 (including) 1.0_rc2 (including)
Punbb Punbb 1.1 (including) 1.1 (including)
Punbb Punbb 1.1.1 (including) 1.1.1 (including)
Punbb Punbb 1.1.2 (including) 1.1.2 (including)
Punbb Punbb 1.1.3 (including) 1.1.3 (including)
Punbb Punbb 1.1.4 (including) 1.1.4 (including)
Punbb Punbb 1.1.5 (including) 1.1.5 (including)
Punbb Punbb 1.2 (including) 1.2 (including)
Punbb Punbb 1.2.1 (including) 1.2.1 (including)
Punbb Punbb 1.2.2 (including) 1.2.2 (including)
Punbb Punbb 1.2.3 (including) 1.2.3 (including)
Punbb Punbb 1.2.4 (including) 1.2.4 (including)
Punbb Punbb 1.2.5 (including) 1.2.5 (including)
Punbb Punbb 1.2.6 (including) 1.2.6 (including)
Punbb Punbb 1.2.7 (including) 1.2.7 (including)
Punbb Punbb 1.2.8 (including) 1.2.8 (including)
Punbb Punbb 1.2.9 (including) 1.2.9 (including)
Punbb Punbb 1.2.10 (including) 1.2.10 (including)
Punbb Punbb 1.2.11 (including) 1.2.11 (including)
Punbb Punbb 1.2.12 (including) 1.2.12 (including)
Punbb Punbb 1.2.13 (including) 1.2.13 (including)
Punbb Punbb 1.2.14 (including) 1.2.14 (including)
Punbb Punbb 1.2.15 (including) 1.2.15 (including)
Punbb Punbb 1.2.16 (including) 1.2.16 (including)

References