CVE-2004-1143
published 2004-12-31CVE-2004-1143: The password generation in mailman before 2.1.5 generates only 5 million unique passwords, which makes it easier for remote attackers to guess passwords via a…
PriorityP424high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.62%
73.5th percentile
The password generation in mailman before 2.1.5 generates only 5 million unique passwords, which makes it easier for remote attackers to guess passwords via a brute force attack.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
| gnu | mailman | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
CAPEC
Password Brute Forcing
mitre_capec
[HIGH] Password Brute Forcing
CAPEC-49: Password Brute Forcing
An adversary tries every possible value for a password until they succeed. A brute force attack, if feasible computationally, will always be successful because it will essentially go through all possible passwords given the alphabet used (lower case letters, upper case letters, numbers, symbols, etc.) and the maximum length of the password.
Execution Flow:
Step 1 [Explore]: [Determine application's/system's password policy] Determine the password policies of the target application/system.
Technique: Determine minimum and maximum allowed password lengths.
Technique: Determine format of allowed passwords (whether they are required or allowed to contain numbers, special characters, etc.).
Technique: Determine account lockout policy (a strict account lockout
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=286796http://marc.info/?l=bugtraq&m=110549296126351&w=2http://secunia.com/advisories/13603/http://www.novell.com/linux/security/advisories/2005_07_mailman.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/18857http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=286796http://marc.info/?l=bugtraq&m=110549296126351&w=2http://secunia.com/advisories/13603/http://www.novell.com/linux/security/advisories/2005_07_mailman.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/18857
2004-12-31
Published