Pedro Lineu Orso chetcpasswd 2.3.3 does not have a rate limit for client requests, which might allow remote attackers to determine passwords via a dictionary attack.
Weaknesses in this category are related to improper management of system resources.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/30455 | vdb entry |
http://secunia.com/advisories/22967 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/21102 | vdb entry vendor advisory |
http://marc.info/?l=bugtraq&m=116371297325564&w=2 | mailing list |
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=394454 | patch |