The Phonemes mode in Pwgen 2.06 generates predictable passwords, which makes it easier for context-dependent attackers to guess the password via a brute-force attack.
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
Link | Tags |
---|---|
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=726578 | third party advisory mailing list |
http://www.openwall.com/lists/oss-security/2013/06/06/1 | third party advisory mailing list |
http://www.openwall.com/lists/oss-security/2013/10/16/15 | third party advisory mailing list |
https://www.openwall.com/lists/oss-security/2012/01/22/6 | third party advisory mailing list |