All errata/sisyphus/ALT-PU-2016-1073-2
ALT-PU-2016-1073-2

Package update jBCrypt in branch sisyphus

Version0.4-alt1_2jpp8
Published2026-02-04
Max severityMEDIUM
Severity:

Closed issues (2)

CVE-2015-0886
MEDIUM5.0

Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.

Published: 2015-02-28Modified: 2025-04-12
CVSS 2.0MEDIUM 5.0
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:N/A:N
References