← Back

CVE-2012-2317

nvd nist
Published: Aug 7, 2012Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

The Debian php_crypt_revamped.patch patch for PHP 5.3.x, as used in the php5 package before 5.3.3-7+squeeze4 in Debian GNU/Linux squeeze, the php5 package before 5.3.2-1ubuntu4.17 in Ubuntu 10.04 LTS, and the php5 package before 5.3.5-1ubuntu7.10 in Ubuntu 11.04, does not properly handle an empty salt string, which might allow remote attackers to bypass authentication by leveraging an application that relies on the PHP crypt function to choose a salt for password hashing.

Affected (9)

2 products
Debian Linux
Php5 Common
2 products
Php5
Ubuntu Linux
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Debian
Up to 5.3.2-1
Version 5.3.3-7+squeeze4
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Up to 5.3.2-1ubuntu4.16
Version 5.3.2-1ubuntu4.17
Version 10.04
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Up to 5.3.5-1ubuntu7.9
Version 5.3.5-1ubuntu7.10
Version 11.04

Related CWEs

References (8)

Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.