The Debian php_crypt_revamped.patch patch for PHP 5.3.x, as used in the php5 package prior to 5.3.3-7+squeeze4 in Debian GNU/Linux squeeze, the php5 package prior to 5.3.2-1ubuntu4.17 in Ubuntu 10.04 LTS, and the php5 package prior to 5.3.5-1ubuntu7.10 in Ubuntu 11.04, does not properly handle an empty salt string, which might allow remote malicious users to bypass authentication by leveraging an application that relies on the PHP crypt function to choose a salt for password hashing.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
debian php5-common 5.3.3-7\\+squeeze4 |
||
debian php5-common |
||
debian debian linux |
||
canonical ubuntu linux 10.04 |
||
canonical php5 5.3.2-1ubuntu4.17 |
||
canonical php5 |
||
canonical php5 5.3.5-1ubuntu7.10 |
||
canonical ubuntu linux 11.04 |