Vulnerability Details CVE-2004-2394
Off-by-one error in passwd 0.68 and earlier, when using the --stdin option, causes passwd to use the first 78 characters of a password instead of the first 79, which results in a small reduction of the search space required for brute force attacks.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 24.2%
CVSS Severity
CVSS v2 Score 2.1
Products affected by CVE-2004-2394
-
cpe:2.3:a:mandrakesoft:mandrake_multi_network_firewall:8.2
-
cpe:2.3:o:mandrakesoft:mandrake_linux:10.0
-
cpe:2.3:o:mandrakesoft:mandrake_linux:8.2
-
cpe:2.3:o:mandrakesoft:mandrake_linux:9.0
-
cpe:2.3:o:mandrakesoft:mandrake_linux:9.1
-
cpe:2.3:o:mandrakesoft:mandrake_linux:9.2
-
cpe:2.3:o:mandrakesoft:mandrake_linux_corporate_server:2.1