First published: Fri Apr 14 2000(Updated: )
The crypt function in QNX uses weak encryption, which allows local users to decrypt passwords.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Qnx Qnx | =4.25a | |
=4.25a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0250 is considered a high severity vulnerability due to weak encryption allowing local users to decrypt passwords.
To mitigate CVE-2000-0250, it is recommended to upgrade to a version of QNX that addresses this encryption weakness.
Local users of QNX version 4.25a are affected by CVE-2000-0250 due to its use of weak encryption in the crypt function.
The impact of CVE-2000-0250 allows unauthorized local users to decrypt user passwords, potentially compromising user accounts.
There are no known workarounds for CVE-2000-0250, and updating the software is the primary method of remediation.