CVE-2012-2742
EPSS 1.8%
描述
Revelation 0.4.13-2 and earlier uses only the first 32 characters of a password followed by a sequence of zeros, which reduces the entropy and makes it easier for context-dependent attackers to crack passwords and obtain access to keys via a brute-force attack.
如何修補 CVE-2012-2742
要修補 CVE-2012-2742,請將受影響套件升級到下列已修補版本。
- Debian/revelation—升級至 0.4.11-10 或更新版本
CVE-2012-2742 正在被利用嗎?
低 — EPSS 為 1.8%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 0.4.11-10