CounterPane PasswordSafe 1.x and 2.x allows local users to test possible encryption keys against a subset of the stored key data without performing the more expensive key derivation function (KDF) function, which reduces the search time in brute force attacks.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/15455 | vdb entry |
http://www.osvdb.org/21244 | vdb entry |
http://securityreason.com/securityalert/190 | third party advisory |
http://marc.info/?l=bugtraq&m=113217074200452&w=2 | mailing list |