CVE-2016-2379
high
CVSS v3
8.8
CVSS v2
3.3
VIR risk
8.8
Description
The Mxit protocol uses weak encryption when encrypting user passwords, which might allow attackers to (1) decrypt hashed passwords by leveraging knowledge of client registration codes or (2) gain login access by eavesdropping on login messages and re-using the hashed passwords.
Predictions
Exploit likelihood
82%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cret@cert.org — https://pidgin.im/news/security/?id=95
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| pidgin | mxit | - | |
References
- http://www.securityfocus.com/bid/91335
- http://www.talosintelligence.com/reports/TALOS-2016-0122/
- https://pidgin.im/news/security/?id=95
- https://security.gentoo.org/glsa/201701-38
- http://www.securityfocus.com/bid/91335
- http://www.talosintelligence.com/reports/TALOS-2016-0122/
- https://pidgin.im/news/security/?id=95
- https://security.gentoo.org/glsa/201701-38
CWEs
CWE-326
Verify integrity in audit chain (admin only). AS-IS.