Weak Password Limitations in Revelation Password Manager by Genii Software
CVE-2012-2742

Currently unrated

Key Information:

Vendor
CVE Published:
27 June 2012

What is CVE-2012-2742?

Revelation Password Manager versions 0.4.13-2 and earlier are susceptible to a significant vulnerability where the effective password length is restricted to just 32 characters. This limitation, combined with a padding of zeros, drastically reduces the entropy of stored passwords, making it easier for attackers to utilize brute-force methods to crack them. The vulnerability exposes users' sensitive encryption keys, allowing context-dependent attackers to gain unauthorized access. The lack of iteration through a strong hashing algorithm, such as SHA, further exacerbates the security issues associated with the password management functionality.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.