CVE-2008-3188
Severity CVSS v4.0:
Pending analysis
Type:
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
Publication date:
22/07/2008
Last modified:
09/04/2025
Description
libxcrypt in SUSE openSUSE 11.0 uses the DES algorithm when the configuration specifies the MD5 algorithm, which makes it easier for attackers to conduct brute-force attacks against hashed passwords.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:opensuse:opensuse:11.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00008.html
- http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00001.html
- http://secunia.com/advisories/31096
- http://secunia.com/advisories/31339
- http://www.securityfocus.com/bid/30301
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43927
- http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00008.html
- http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00001.html
- http://secunia.com/advisories/31096
- http://secunia.com/advisories/31339
- http://www.securityfocus.com/bid/30301
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43927



