CVE-2015-0886
published 2015-02-28CVE-2015-0886: Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0.4 makes it easier for remote attackers to determine cleartext…
PriorityP428medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
4.80%
91.0th percentile
Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libjbcrypt-java | < libjbcrypt-java 0.4-1 (bookworm) | libjbcrypt-java 0.4-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| jenkins | ant_plugin | — | — |
| jenkins | jenkins_core | — | — |
| jenkins | jenkins_lts | — | — |
| mindrot | jbcrypt | < 0.4 | 0.4 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Jenkins
Jenkins Security Advisory 2017-02-01
vendor_jenkins·2017-02-01·CVSS 4.3
CVE-2011-4969 [MEDIUM] Jenkins Security Advisory 2017-02-01
Title: Jenkins Security Advisory 2017-02-01
Jenkins Security Advisory 2017-02-01
This advisory announces multiple vulnerabilities in Jenkins.
Description
Use of AES ECB block cipher mode without IV for encrypting secrets
SECURITY-304 / CVE-2017-2598
Secrets such as passwords are typically stored on disk and sent to users as part of some pages in encrypted form. These were encrypted using AES-128 ECB without IV, which exposes Jenkins and the stored secrets to unnecessary risks. Jenkins now encrypts secrets using AES-128 CBC with random IV.
Items could be created with same name as existing item
SECURITY-321 / CVE-2017-2599
An insufficient permission check allowed users with the permission to create new items (e.g. jobs) to overwrite
Red Hat
jBCrypt: integer overflow in the crypt_raw method
vendor_redhat·2015-02-27·CVSS 5.0
CVE-2015-0886 [MEDIUM] CWE-190 jBCrypt: integer overflow in the crypt_raw method
jBCrypt: integer overflow in the crypt_raw method
Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.
Package: jbcrypt (Red Hat JBoss Operations Network 3) - Not affected
Package: jenkins (Red Hat OpenShift Enterprise 2) - Under investigation
Debian
CVE-2015-0886: libjbcrypt-java - Integer overflow in the crypt_raw method in the key-stretching implementation in...
vendor_debian·2015·CVSS 5.0
CVE-2015-0886 [MEDIUM] CVE-2015-0886: libjbcrypt-java - Integer overflow in the crypt_raw method in the key-stretching implementation in...
Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.
Scope: local
bookworm: resolved (fixed in 0.4-1)
bullseye: resolved (fixed in 0.4-1)
forky: resolved (fixed in 0.4-1)
sid: resolved (fixed in 0.4-1)
trixie: resolved (fixed in 0.4-1)
OSV
Integer Overflow or Wraparound in JBCrypt
osv·2022-05-13
CVE-2015-0886 [MEDIUM] Integer Overflow or Wraparound in JBCrypt
Integer Overflow or Wraparound in JBCrypt
Integer overflow in the crypt_raw method in the key-stretching implementation in JBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.
GHSA
Integer Overflow or Wraparound in JBCrypt
ghsa·2022-05-13
CVE-2015-0886 [MEDIUM] CWE-190 Integer Overflow or Wraparound in JBCrypt
Integer Overflow or Wraparound in JBCrypt
Integer overflow in the crypt_raw method in the key-stretching implementation in JBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.
OSV
CVE-2015-0886: Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0
osv·2015-02-28·CVSS 5.0
CVE-2015-0886 [MEDIUM] CVE-2015-0886: Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0
Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-0886 jBCrypt: integer overflow in the crypt_raw method [fedora-all]
bugzilla·2015-03-02·CVSS 5.0
CVE-2015-0886 [MEDIUM] CVE-2015-0886 jBCrypt: integer overflow in the crypt_raw method [fedora-all]
CVE-2015-0886 jBCrypt: integer overflow in the crypt_raw method [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of F
Bugzilla
CVE-2015-0886 jBCrypt: integer overflow in the crypt_raw method
bugzilla·2015-03-02·CVSS 5.0
CVE-2015-0886 [MEDIUM] CVE-2015-0886 jBCrypt: integer overflow in the crypt_raw method
CVE-2015-0886 jBCrypt: integer overflow in the crypt_raw method
Common Vulnerabilities and Exposures assigned an identifier CVE-2015-0886 to
the following vulnerability:
Name: CVE-2015-0886
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0886
Assigned: 20150108
Reference: http://jvndb.jvn.jp/jvndb/JVNDB-2015-000033
Integer overflow in the crypt_raw method in the key-stretching
implementation in jBCrypt before 0.4 makes it easier for remote
attackers to determine cleartext values of password hashes via a
brute-force attack against hashes associated with the maximum
exponent.
Discussion:
Created jBCrypt tracking bugs for this issue:
Affects: fedora-all [bug 1197816]
---
jBCrypt-0.4-1.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, pleas
http://jvn.jp/en/jp/JVN77718330/index.htmlhttp://jvndb.jvn.jp/jvndb/JVNDB-2015-000033http://lists.fedoraproject.org/pipermail/package-announce/2015-March/151496.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/151786.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/151797.htmlhttp://www.mindrot.org/projects/jBCrypt/news/rel04.htmlhttps://bugzilla.mindrot.org/show_bug.cgi?id=2097https://lists.apache.org/thread.html/rbd23e3ac8113b4da0a025c0e45170b6ec317383a1cf06090c2c717aa%40%3Ccommits.cassandra.apache.org%3Ehttps://lists.apache.org/thread.html/rd5c2256b8dc9935e4bb5e9be90adce58408054bb42523730a40c5548%40%3Ccommits.cassandra.apache.org%3Ehttps://lists.apache.org/thread.html/re330cfe9e5d84e3f7da8ace23ec32f38cb3fbd328bf177badd7ad942%40%3Ccommits.cassandra.apache.org%3Ehttp://jvn.jp/en/jp/JVN77718330/index.htmlhttp://jvndb.jvn.jp/jvndb/JVNDB-2015-000033http://lists.fedoraproject.org/pipermail/package-announce/2015-March/151496.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/151786.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/151797.htmlhttp://www.mindrot.org/projects/jBCrypt/news/rel04.htmlhttps://bugzilla.mindrot.org/show_bug.cgi?id=2097https://lists.apache.org/thread.html/rbd23e3ac8113b4da0a025c0e45170b6ec317383a1cf06090c2c717aa%40%3Ccommits.cassandra.apache.org%3Ehttps://lists.apache.org/thread.html/rd5c2256b8dc9935e4bb5e9be90adce58408054bb42523730a40c5548%40%3Ccommits.cassandra.apache.org%3Ehttps://lists.apache.org/thread.html/re330cfe9e5d84e3f7da8ace23ec32f38cb3fbd328bf177badd7ad942%40%3Ccommits.cassandra.apache.org%3E
2015-02-28
Published