Weak Password Limitations in Revelation Password Manager by Genii Software
CVE-2012-2742
Currently unrated
What is CVE-2012-2742?
Revelation Password Manager versions 0.4.13-2 and earlier are susceptible to a significant vulnerability where the effective password length is restricted to just 32 characters. This limitation, combined with a padding of zeros, drastically reduces the entropy of stored passwords, making it easier for attackers to utilize brute-force methods to crack them. The vulnerability exposes users' sensitive encryption keys, allowing context-dependent attackers to gain unauthorized access. The lack of iteration through a strong hashing algorithm, such as SHA, further exacerbates the security issues associated with the password management functionality.
