CVE Vulnerabilities

CVE-2009-4269

Published: Aug 16, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The password hash generation algorithm in the BUILTIN authentication functionality for Apache Derby before 10.6.1.0 performs a transformation that reduces the size of the set of inputs to SHA-1, which produces a small search space that makes it easier for local and possibly remote attackers to crack passwords by generating hash collisions, related to password substitution.

Affected Software

NameVendorStart VersionEnd Version
DerbyApache*10.5.3.0 (including)
Sun-javadbUbuntuesm-apps/xenial*
Sun-javadbUbuntuhardy*
Sun-javadbUbuntujaunty*
Sun-javadbUbuntukarmic*
Sun-javadbUbuntulucid*
Sun-javadbUbuntumaverick*
Sun-javadbUbuntunatty*
Sun-javadbUbuntuoneiric*
Sun-javadbUbuntuprecise*
Sun-javadbUbuntuquantal*
Sun-javadbUbunturaring*
Sun-javadbUbuntusaucy*
Sun-javadbUbuntutrusty*
Sun-javadbUbuntuupstream*
Sun-javadbUbuntuutopic*
Sun-javadbUbuntuvivid*
Sun-javadbUbuntuwily*
Sun-javadbUbuntuxenial*
Sun-javadbUbuntuyakkety*

References