High severity7.5NVD Advisory· Published Feb 19, 2022· Updated Jun 17, 2026
CVE-2016-20013
CVE-2016-20013
Description
sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- sha256crypt and sha512crypt/sha256crypt and sha512cryptdescription
Patches
Vulnerability mechanics
References
3- akkadia.org/drepper/SHA-crypt.txtnvdExploitThird Party Advisory
- pthree.org/2018/05/23/do-not-use-sha256crypt-sha512crypt-theyre-dangerous/nvdExploitThird Party Advisory
- twitter.com/solardiz/status/795601240151457793nvdThird Party Advisory
News mentions
0No linked articles in our index yet.