CVE-2008-3188 describes a cryptographic weakness in libxcrypt within SUSE openSUSE 11.0, where the system incorrectly uses the weaker DES algorithm instead of the configured MD5 algorithm for password hashing. This flaw significantly lowers the security of hashed passwords, making them more susceptible to brute-force attacks. With a CVSS score of 7.5 (HIGH), the vulnerability is remotely exploitable with low attack complexity, allowing unauthorized access to sensitive information. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this decade-old vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.0CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:11.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.