core-sdi.mysql...

- AV AC AU C I A
发布: 2000-10-27
修订: 2025-04-13

Core SDI Advisory CORE-20001023 - The "MySQL Database Engine" uses an authentication scheme designed to prevent the flow of plaintext passwords over the network and the storage of them in plaintext. For that purpose a challenge-response mechanism for authentication has been implemented on all versions of MySQL. The authentication mechanism is not cryptographically strong. Each time a user executes this mechanism, information allowing an attacker to recover this user's password is leaked. Fix available here.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息