Red Hat Security Advisory 2011-1378-01

0
77

Red Hat Security Advisory 2011-1378-01 – PostgreSQL is an advanced object-relational database management system. A signedness issue was found in the way the crypt() function in the PostgreSQL pgcrypto module handled 8-bit characters in passwords when using Blowfish hashing. Up to three characters immediately preceding a non-ASCII character had no effect on the hash result, thus shortening the effective password length. This made brute-force guessing more efficient as several different passwords were hashed to the same value.

Source: Red Hat Security Advisory 2011-1378-01