First published: Fri Nov 22 2019(Updated: )
W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the hashes.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Boldgrid W3 Total Cache | <0.9.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2012-6078 is high with a severity value of 7.5.
CVE-2012-6078 affects W3 Total Cache versions up to and including 0.9.2.5.
The vulnerability in CVE-2012-6078 is that W3 Total Cache generates hash keys insecurely, allowing remote attackers to predict the values of the hashes.
To fix CVE-2012-6078, it is recommended to update W3 Total Cache to version 0.9.2.6 or later.
You can find more information about CVE-2012-6078 in the references provided: [1](https://www.openwall.com/lists/oss-security/2012/12/30/3), [2](https://security-tracker.debian.org/tracker/CVE-2012-6078), [3](http://www.openwall.com/lists/oss-security/2012/12/30/3).