Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2008-3188

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Novell openSUSE是美国Novell公司的一套基于Linux的自由操作系统。 openSUSE使用libxcrypt库计算口令的哈希值,可以配置为使用DES、MD5或blowfish。由于libxcrypt库中的一个漏洞,即使/etc/default/passwd文件中已经配置了MD5,系统仍会忽略这个设置使用DES算法。相对较弱的算法可能有助于攻击者的暴力破解。

AI Predicted 7.5 Difficulty: Easy EPSS 1.50% · P72
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2008-3188

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
libxcrypt in SUSE openSUSE 11.0 uses the DES algorithm when the configuration specifies the MD5 algorithm, which makes it easier for attackers to conduct brute-force attacks against hashed passwords.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
openSUSE libxcrypt 加密问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Novell openSUSE是美国Novell公司的一套基于Linux的自由操作系统。 openSUSE使用libxcrypt库计算口令的哈希值,可以配置为使用DES、MD5或blowfish。由于libxcrypt库中的一个漏洞,即使/etc/default/passwd文件中已经配置了MD5,系统仍会忽略这个设置使用DES算法。相对较弱的算法可能有助于攻击者的暴力破解。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2008-3188

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2008-3188

登录查看更多情报信息。

Vendor Advisories for CVE-2008-3188 (4)

Mailing List Discussions for CVE-2008-3188 (2)

Same Patch Batch · n/a · 2008-07-22 · 12 CVEs total

CVE-2008-3263 Asterisk IAX POKE请求远程拒绝服务漏洞
CVE-2008-3260 Claroline 多文件跨站漏洞
CVE-2008-3261 Claroline claroline/redirector.php 重定向攻击漏洞
CVE-2008-3262 claroline 跨站请求伪造漏洞
CVE-2008-3253 Citrix XenServer XenAPI HTTP接口跨站脚本漏洞
CVE-2008-3254 preCMS 'id' Parameter SQL注入漏洞
CVE-2008-3255 LunarNight Laboratory WebProxy 跨站脚本漏洞
CVE-2008-3256 Siteframe 'folder.php' SQL注入漏洞
CVE-2008-3257 Oracle Weblogic Apache连接器POST请求远程栈溢出漏洞
CVE-2008-3258 Zoph 多个SQL注入漏洞
CVE-2008-3259 OpenSSH X11UseLocalhost X11转发会话劫持漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2008-3188

No comments yet


Leave a comment