4.3
CVSSv2

CVE-2012-2317

Published: 07/08/2012 Updated: 08/08/2012
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The Debian php_crypt_revamped.patch patch for PHP 5.3.x, as used in the php5 package prior to 5.3.3-7+squeeze4 in Debian GNU/Linux squeeze, the php5 package prior to 5.3.2-1ubuntu4.17 in Ubuntu 10.04 LTS, and the php5 package prior to 5.3.5-1ubuntu7.10 in Ubuntu 11.04, does not properly handle an empty salt string, which might allow remote malicious users to bypass authentication by leveraging an application that relies on the PHP crypt function to choose a salt for password hashing.

Vulnerable Product Search on Vulmon Subscribe to Product

debian php5-common 5.3.3-7\\+squeeze4

debian php5-common

debian debian linux

canonical ubuntu linux 10.04

canonical php5 5.3.2-1ubuntu4.17

canonical php5

canonical php5 5.3.5-1ubuntu7.10

canonical ubuntu linux 11.04

Vendor Advisories

Several security issues were fixed in PHP ...