Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.
| Software | From | Fixed in |
|---|---|---|
| mindrot / jbcrypt | - | 0.4 |
| fedoraproject / fedora | 22 | 22.x |
| fedoraproject / fedora | 20 | 20.x |
| fedoraproject / fedora | 21 | 21.x |
org.mindrot / jbcrypt
|
- | 0.4 |