CVE-2006-1058

CWE-9169 documents7 sources
Severity
5.5MEDIUM
EPSS
0.0%
top 86.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 4
Latest updateMay 1

Description

BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

🔴Vulnerability Details

3
GHSA
GHSA-25qj-gfr4-9mhj: BusyBox 12022-05-01
OSV
CVE-2006-1058: BusyBox 12006-04-04
CVEList
CVE-2006-1058: BusyBox 12006-04-04

📋Vendor Advisories

2
Debian
CVE-2006-1058: busybox - BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easi...2006
Red Hat
security flaw2005-12-19

💬Community

3
Bugzilla
CVE-2006-1058 security flaw2018-08-16
Bugzilla
CVE-2006-1058 BusyBox passwd command fails to generate password with salt2006-03-30
Bugzilla
CVE-2006-1058 BusyBox passwd command fails to generate password with salt2006-03-30