iOpus insecure password encryption

iopus-insecure-passwords (26266) The risk level is classified as LowLow Risk

Description:

iOpus Secure Email Attachments (SEA) uses an insecure encryption algorithm. If a password is used that contains repeated character strings, an attacker could decrypt the protected file using only a portion of the repeated character string.


Consequences:

Bypass Security

Remedy:

No remedy available as of July 9, 2011.

References:

  • BugTraq Mailing List, Sat Apr 22 2006 - 11:25:16 CDT: ADVISORY FOR IOPUS SECURE EMAIL ATTACHMENTS.
  • iOpus Web site: iOpus Secure Email Attachments.
  • BID-17656: iOpus Secure Email Attachments Encryption Weakness
  • CVE-2006-2036: iOpus Secure Email Attachments (SEA), probably 1.0, does not properly handle passwords that consist of repetitions of a substring, which allows attackers to decrypt files by entering only the substring.
  • SA19771: iOpus Secure Email Attachments Password Usage Security Issue
  • SECTRACK ID: 1015980: iOpus Secure Email Attachments Password Weakness May Let Remote Users Decrypt Attachments

Platforms Affected:

  • iOpus GmbH iOpus Secure Email Attachments (SEA) 1.0

Reported:

Apr 22, 2006

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page