Candidate: CVE-2012-2743 PublicDate: 2012-06-27 22:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2743 http://www.openwall.com/lists/oss-security/2012/06/18/1 Description: Revelation 0.4.13-2 and earlier does not iterate through SHA hashing algorithms for AES encryption, which makes it easier for context-dependent attackers to guess passwords via a brute force attack. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=633088 https://bugs.launchpad.net/bugs/1014326 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_revelation: upstream_revelation: released (0.4.14) hardy_revelation: ignored (reached end-of-life) lucid_revelation: ignored (reached end-of-life) natty_revelation: ignored (reached end-of-life) oneiric_revelation: ignored (reached end-of-life) precise_revelation: ignored (reached end-of-life) precise/esm_revelation: DNE (precise was needed) quantal_revelation: ignored (reached end-of-life) raring_revelation: ignored (reached end-of-life) saucy_revelation: ignored (reached end-of-life) trusty_revelation: not-affected (0.4.14-2) trusty/esm_revelation: DNE (trusty was not-affected [0.4.14-2]) utopic_revelation: ignored (reached end-of-life) vivid_revelation: ignored (reached end-of-life) vivid/stable-phone-overlay_revelation: DNE vivid/ubuntu-core_revelation: DNE wily_revelation: ignored (reached end-of-life) xenial_revelation: not-affected (0.4.14-2) yakkety_revelation: ignored (reached end-of-life) zesty_revelation: ignored (reached end-of-life) artful_revelation: ignored (reached end-of-life) bionic_revelation: not-affected (0.4.14-2) cosmic_revelation: not-affected (0.4.14-2) devel_revelation: not-affected (0.4.14-2)