All posts by Blake Swopes

Blake Swopes is a disabled former Linux Systems Administrator from Southern California. Due to chronic pain, he can no longer spend much time on a keyboard, so this site has become largely archival.

CA-2000-01 Poor Error Handling in Password Authentication May Result in Authentication Failure

This advisory is being published jointly by the CUSERT Coordination Center,
d0d-CERT, and the d0d Joint Task Force for Computer User Stupidity (JTF-CUS).

Original release date: February 19, 2000

Last revised: December 25, 2012

A complete revision history is at the end of this file.

Systems Affected

  • ASCII based Password Authentication Modules

Overview

Poor error handling in many Password Authentication Modules which rely
on ASCII based data-input may result in a failure to authenticate users.
This could result in a denial of service to those users.

Continue reading CA-2000-01 Poor Error Handling in Password Authentication May Result in Authentication Failure