---
title: "CVE-2008-6792\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2008-6792?format=md
keywords: index, follow
---

# CVE-2008-6792

Publication date 7 May 2009

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

system-tools-backends before 2.6.0-1ubuntu1.1 in Ubuntu 8.10, as used by
"Users and Groups" in GNOME System Tools, hashes account passwords with
3DES and consequently limits effective password lengths to eight
characters, which makes it easier for context-dependent attackers to
successfully conduct brute-force password attacks.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| system-tools-backends | 9.04 jaunty | Not affected |
| 8.10 intrepid | Fixed 2.6.0-1ubuntu1.1 |
| 8.04 LTS hardy | Not affected |
| 6.06 LTS dapper | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-6792)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2008-6792)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2008-6792)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2008-6792)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2008-6792>
