CVE-2016-20013
19.02.2022, 05:15
sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password.Enginsight
| Vendor | Product | Version |
|---|---|---|
| sha256crypt_project | sha256crypt | 𝑥 ≤ 0.6 |
| sha512crypt_project | sha512crypt | 𝑥 ≤ 0.6 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| dietlibc |
| ||||||||||||||||||||
| eglibc |
| ||||||||||||||||||||
| glibc |
| ||||||||||||||||||||
| sssd |
| ||||||||||||||||||||
| syslinux |
| ||||||||||||||||||||
| syslinux-legacy |
| ||||||||||||||||||||
| uclibc |
| ||||||||||||||||||||
| zabbix |
|
References