CVE-2016-20013
19.02.2022, 05:15
sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password.Enginsight
Vendor | Product | Version |
---|---|---|
sha256crypt_project | sha256crypt | 𝑥 ≤ 0.6 |
sha512crypt_project | sha512crypt | 𝑥 ≤ 0.6 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
dietlibc |
| ||||||||||||||||||||
eglibc |
| ||||||||||||||||||||
glibc |
| ||||||||||||||||||||
sssd |
| ||||||||||||||||||||
syslinux |
| ||||||||||||||||||||
syslinux-legacy |
| ||||||||||||||||||||
uclibc |
| ||||||||||||||||||||
zabbix |
|
References