CVE-2006-1058
published 2006-04-04CVE-2006-1058: BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using…
PriorityP416medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.29%
21.5th percentile
BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| avaya | aura_application_enablement_services | — | — |
| avaya | aura_application_enablement_services | — | — |
| avaya | aura_sip_enablement_services | < 5.0 | 5.0 |
| avaya | messaging_storage_server | >= 3.0 < 4.0 | 4.0 |
| busybox | busybox | — | — |
| busybox | busybox | >= 0 < 1:1.1.3-1 | 1:1.1.3-1 |
| busybox | busybox | >= 0 < 1:1.1.3-1 | 1:1.1.3-1 |
| busybox | busybox | >= 0 < 1:1.1.3-1 | 1:1.1.3-1 |
| busybox | busybox | >= 0 < 1:1.1.3-1 | 1:1.1.3-1 |
| debian | busybox | < busybox 1:1.1.3-1 (bookworm) | busybox 1:1.1.3-1 (bookworm) |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2006-1058: busybox - BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easi...
vendor_debian·2006·CVSS 5.5
CVE-2006-1058 [MEDIUM] CVE-2006-1058: busybox - BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easi...
BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.
Scope: local
bookworm: resolved (fixed in 1:1.1.3-1)
bullseye: resolved (fixed in 1:1.1.3-1)
forky: resolved (fixed in 1:1.1.3-1)
sid: resolved (fixed in 1:1.1.3-1)
trixie: resolved (fixed in 1:1.1.3-1)
Red Hat
security flaw
vendor_redhat·2005-12-19·CVSS 5.5
CVE-2006-1058 [MEDIUM] security flaw
security flaw
BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.
Statement: Red Hat is aware of this issue and is tracking it via the following bug:
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=187385
The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw. More information regarding issue severity can be found here:
http://www.redhat.com/security/updates/classification/
This issue does not affect Red Hat Enterprise Linux 2.1 or 3.
GHSA
GHSA-25qj-gfr4-9mhj: BusyBox 1
ghsa_unreviewed·2022-05-01
CVE-2006-1058 [LOW] CWE-916 GHSA-25qj-gfr4-9mhj: BusyBox 1
BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.
OSV
CVE-2006-1058: BusyBox 1
osv·2006-04-04·CVSS 5.5
CVE-2006-1058 [MEDIUM] CVE-2006-1058: BusyBox 1
BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-1058 security flaw
bugzilla·2018-08-16·CVSS 5.5
CVE-2006-1058 [MEDIUM] CVE-2006-1058 security flaw
CVE-2006-1058 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.
---
Statement:
Red Hat is aware of this issue and is tracking it via the following bug:
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=187385
The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw. More information regarding issue severity can be found here:
http://www.redhat.com/security/updates/classification/
This issue does not affect
Bugzilla
CVE-2006-1058 BusyBox passwd command fails to generate password with salt
bugzilla·2006-03-30·CVSS 5.5
CVE-2006-1058 [MEDIUM] CVE-2006-1058 BusyBox passwd command fails to generate password with salt
CVE-2006-1058 BusyBox passwd command fails to generate password with salt
BusyBox passwd command fails to generate password with salt
The BusyBox passwd command does not use a proper salt when generating
passwords. This would create an instance where a brute force attack
could take very little time.
http://bugs.busybox.net/view.php?id=604
We don't do this during install, this issue should have very minimal
impact. This issue is also mitigated by the fact that it's only an
issue if an attacker has a copy of the shadow file.
Discussion:
This request was evaluated by Red Hat Product Management for inclusion in a Red
Hat Enterprise Linux maintenance release. Product Management has requested
further review of this request by Red Hat Engineering, for potential
inclusion in a Red Hat Enterpr
Bugzilla
CVE-2006-1058 BusyBox passwd command fails to generate password with salt
bugzilla·2006-03-30·CVSS 5.5
CVE-2006-1058 [MEDIUM] CVE-2006-1058 BusyBox passwd command fails to generate password with salt
CVE-2006-1058 BusyBox passwd command fails to generate password with salt
BusyBox passwd command fails to generate password with salt
The BusyBox passwd command does not use a proper salt when generating
passwords. This would create an instance where a brute force attack
could take very little time.
http://bugs.busybox.net/view.php?id=604
We don't do this during install, this issue should have very minimal
impact. This issue is also mitigated by the fact that it's only an
issue if an attacker has a copy of the shadow file.
This issue also affects FC4
Discussion:
This bug is fixed in devel version - busybox-1.1.1-1, fc5 - busybox-1.01-3.fc5
and fc4 - busybox-1.00-5.fc4.
CWE
Use of a One-Way Hash without a Salt
mitre_cwe
CWE-759 Use of a One-Way Hash without a Salt
CWE-759: Use of a One-Way Hash without a Salt
The product uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does not also use a salt as part of the input.
This makes it easier for attackers to pre-compute the hash value using dictionary attack techniques such as rainbow tables. It should be noted that, despite common perceptions, the use of a good salt with a hash does not sufficiently increase the effort for an attacker who is targeting an individual password, or who has a large amount of computing resources available, such as with cloud-based services or specialized, inexpensive hardware. Offline password cracking can still be effective if the hash function is not expensive to compute; many cryptographic functions are
CWE
Use of Password Hash With Insufficient Computational Effort
mitre_cwe
CWE-916 Use of Password Hash With Insufficient Computational Effort
CWE-916: Use of Password Hash With Insufficient Computational Effort
The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.
Many password storage mechanisms compute a hash and store the hash, instead of storing the original password in plaintext. In this design, authentication involves accepting an incoming password, computing its hash, and comparing it to the stored hash. Many hash algorithms are designed to execute quickly with minimal overhead, even cryptographic hashes. However, this efficiency is a problem for password storage, because it can reduce an attacker's workload for brute-force password cracking. If an attacker can obtain the hashes
CAPEC
Rainbow Table Password Cracking
mitre_capec
[MEDIUM] Rainbow Table Password Cracking
CAPEC-55: Rainbow Table Password Cracking
An attacker gets access to the database table where hashes of passwords are stored. They then use a rainbow table of pre-computed hash chains to attempt to look up the original password. Once the original password corresponding to the hash is obtained, the attacker uses the original password to gain access to the system.
Execution Flow:
Step 1 [Explore]: [Determine application's/system's password policy] Determine the password policies of the target application/system.
Technique: Determine minimum and maximum allowed password lengths.
Technique: Determine format of allowed passwords (whether they are required or allowed to contain numbers, special characters, etc.).
Technique: Determine account lockout policy (a strict account lockout policy will
http://bugs.busybox.net/view.php?id=604http://secunia.com/advisories/19477http://secunia.com/advisories/25098http://secunia.com/advisories/25848http://support.avaya.com/elmodocs2/security/ASA-2007-250.htmhttp://www.redhat.com/support/errata/RHSA-2007-0244.htmlhttp://www.securityfocus.com/bid/17330https://exchange.xforce.ibmcloud.com/vulnerabilities/25569https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9483http://bugs.busybox.net/view.php?id=604http://secunia.com/advisories/19477http://secunia.com/advisories/25098http://secunia.com/advisories/25848http://support.avaya.com/elmodocs2/security/ASA-2007-250.htmhttp://www.redhat.com/support/errata/RHSA-2007-0244.htmlhttp://www.securityfocus.com/bid/17330https://exchange.xforce.ibmcloud.com/vulnerabilities/25569https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9483
2006-04-04
Published