libcrypt is prone to a password-encryption weakness.
Credit:
The original article can be found at: http://www.securityfocus.com/bid/53729
The information has been provided by Rubin Xu, Joseph Bonneau, Donting Yu .
An attacker can leverage this issue to bypass authentication mechanism of application using the affected 'crypt()' function to encrypt its users' passwords. Successful exploits can aid in launching further attacks.
Vendor Status:
Vendor as issued an updated vulnerability.