Retrospect and Retrospect Client before 10.0.2.119 on Windows, before 12.0.2.116 on OS X, and before 10.0.2.104 on Linux improperly generate password hashes, which makes it easier for remote attackers to bypass authentication and obtain access to backup files by leveraging a collision.
References
Link | Resource |
---|---|
http://www.kb.cert.org/vuls/id/101500 | US Government Resource Third Party Advisory |
http://www.retrospect.com/support/kb/cve_2015_2864 | Patch Vendor Advisory |
http://www.securityfocus.com/bid/75201 | |
http://www.securitytracker.com/id/1033948 | |
https://www.youtube.com/watch?v=MB8AL5u7JCA | Exploit |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: certcc
Published: 2015-09-21T10:00:00
Updated: 2016-12-05T21:57:02
Reserved: 2015-04-03T00:00:00
Link: CVE-2015-2864
JSON object: View
NVD Information
Status : Modified
Published: 2015-09-21T10:59:00.100
Modified: 2016-12-07T18:10:48.753
Link: CVE-2015-2864
JSON object: View
Redhat Information
No data.
CWE