CVE-2012-2143
published 2012-07-05CVE-2012-2143: The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete…
PriorityP432medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
5.73%
92.2th percentile
The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.
Affected
66 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| freebsd | freebsd | <= 9.0 | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_ubuntu5.0MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2012-06-19·CVSS 5.0
CVE-2012-0781 [MEDIUM] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: Several security issues were fixed in PHP.
It was discovered that PHP incorrectly handled certain Tidy::diagnose
operations on invalid objects. A remote attacker could use this flaw to
cause PHP to crash, leading to a denial of service. (CVE-2012-0781)
It was discovered that PHP incorrectly handled certain multi-file upload
filenames. A remote attacker could use this flaw to cause a denial of
service, or to perform a directory traversal attack. (CVE-2012-1172)
Rubin Xu and Joseph Bonneau discovered that PHP incorrectly handled certain
Unicode characters in passwords passed to the crypt() function. A remote
attacker could possibly use this flaw to bypass authentication.
(CVE-2012-2143)
It was discovered that a Debian/Ubuntu specific patch caused PHP
Ubuntu
PostgreSQL vulnerabilities
vendor_ubuntu·2012-06-05·CVSS 4.3
CVE-2012-2143 [MEDIUM] PostgreSQL vulnerabilities
Title: PostgreSQL vulnerabilities
Summary: PostgreSQL could be made to crash or incorrectly handle authentication.
It was discovered that PostgreSQL incorrectly handled certain bytes passed
to the crypt() function when using DES encryption. An attacker could use
this flaw to incorrectly handle authentication. (CVE-2012-2143)
It was discovered that PostgreSQL incorrectly handled SECURITY DEFINER and
SET attributes on procedural call handlers. An attacker could use this flaw
to cause PostgreSQL to crash, leading to a denial of service.
(CVE-2012-2655)
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
Red Hat
crypt(): DES encrypted password weakness
vendor_redhat·2012-05-30·CVSS 4.3
CVE-2012-2143 [MEDIUM] crypt(): DES encrypted password weakness
crypt(): DES encrypted password weakness
The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.
Statement: This issue did not affect the version of php as shipped with Red Hat Enterprise Linux 5 as it did not include FreeSec's libcrypt cryptographic algorithms implementation yet. This issue was addressed in php53 package for Red Hat Enterprise Linux 5 via RHSA-2012:1047 and in php package for Red Hat Enterprise Linux 6 via RHSA-2012:1046
BSD
FreeBSD-SA-12:02.crypt: Incorrect crypt() hashing
bsd_advisories·2012-05-30·CVSS 4.3
CVE-2012-2143 [MEDIUM] FreeBSD-SA-12:02.crypt: Incorrect crypt() hashing
FreeBSD-SA-12:02.crypt Security Advisory
The FreeBSD Project
Topic: Incorrect crypt() hashing
Category: core
Module: libcrypt
Announced: 2012-05-30
Credits: Rubin Xu, Joseph Bonneau, Donting Yu
Affects: All supported versions of FreeBSD.
Corrected: 2012-05-30 12:01:28 UTC (RELENG_7, 7.4-STABLE)
2012-05-30 12:01:28 UTC (RELENG_7_4, 7.4-RELEASE-p8)
2012-05-30 12:01:28 UTC (RELENG_8, 8.3-STABLE)
2012-05-30 12:01:28 UTC (RELENG_8_3, 8.3-RELEASE-p2)
2012-05-30 12:01:28 UTC (RELENG_8_2, 8.2-RELEASE-p8)
2012-05-30 12:01:28 UTC (RELENG_8_1, 8.1-RELEASE-p10)
2012-05-30 12:01:28 UTC (RELENG_9, 9.0-STABLE)
2012-05-30 12:01:28 UTC (RELENG_9_0, 9.0-RELEASE-p2)
CVE Name: CVE-2012-2143
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security b
GHSA
GHSA-6rxj-38xv-j69g: The crypt_des (aka DES-based crypt) function in FreeBSD before 9
ghsa_unreviewed·2022-05-17
CVE-2012-2143 [MEDIUM] GHSA-6rxj-38xv-j69g: The crypt_des (aka DES-based crypt) function in FreeBSD before 9
The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2143 CVE-2012-2655 postgresql: various flaws [fedora-all]
bugzilla·2012-05-30·CVSS 4.3
CVE-2012-2143 [MEDIUM] CVE-2012-2143 CVE-2012-2655 postgresql: various flaws [fedora-all]
CVE-2012-2143 CVE-2012-2655 postgresql: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=816
Bugzilla
CVE-2012-2143 BSD crypt(): DES encrypted password weakness [fedora-all]
bugzilla·2012-05-30·CVSS 4.3
CVE-2012-2143 [MEDIUM] CVE-2012-2143 BSD crypt(): DES encrypted password weakness [fedora-all]
CVE-2012-2143 BSD crypt(): DES encrypted password weakness [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bug
Bugzilla
CVE-2012-2143 BSD crypt(): DES encrypted password weakness
bugzilla·2012-04-27·CVSS 4.3
CVE-2012-2143 [MEDIUM] CVE-2012-2143 BSD crypt(): DES encrypted password weakness
CVE-2012-2143 BSD crypt(): DES encrypted password weakness
A security flaw was found in the way DES and extended DES based crypt() password encryption function performed encryption of certain keys, when the key to be encrypted was provided in the Unicode encoding (certain keys were truncated before being DES digested). When the resulting ciphertext for such a previously shortened key was used as a pattern in a password protected resource, intended to be matched against subsequently encrypted value of the password field, retrieved from the user authentication dialog, it could lead to authentication bypass.
Discussion:
This issue affects the versions of the postgresql and postgresql84 packages, as shipped with Red Hat Enterprise Linux 5.
--
This issue affects the version of the posgresq
http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=aab49e934de1fff046e659cbec46e3d053b41c34http://git.postgresql.org/gitweb/?p=postgresql.git&a=commit&h=932ded2ed51e8333852e370c7a6dad75d9f236f9http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-June/082258.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-June/082292.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-June/082294.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-07/msg00003.htmlhttp://lists.opensuse.org/opensuse-updates/2012-09/msg00102.htmlhttp://lists.opensuse.org/opensuse-updates/2012-10/msg00013.htmlhttp://lists.opensuse.org/opensuse-updates/2012-10/msg00024.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1037.htmlhttp://secunia.com/advisories/49304http://secunia.com/advisories/50718http://security.freebsd.org/advisories/FreeBSD-SA-12:02.crypt.aschttp://support.apple.com/kb/HT5501http://www.debian.org/security/2012/dsa-2491http://www.mandriva.com/security/advisories?name=MDVSA-2012:092http://www.postgresql.org/docs/8.3/static/release-8-3-19.htmlhttp://www.postgresql.org/docs/8.4/static/release-8-4-12.htmlhttp://www.postgresql.org/docs/9.0/static/release-9-0-8.htmlhttp://www.postgresql.org/docs/9.1/static/release-9-1-4.htmlhttp://www.postgresql.org/support/security/http://www.securitytracker.com/id?1026995https://bugzilla.redhat.com/show_bug.cgi?id=816956http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=aab49e934de1fff046e659cbec46e3d053b41c34http://git.postgresql.org/gitweb/?p=postgresql.git&a=commit&h=932ded2ed51e8333852e370c7a6dad75d9f236f9http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-June/082258.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-June/082292.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-June/082294.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-07/msg00003.htmlhttp://lists.opensuse.org/opensuse-updates/2012-09/msg00102.htmlhttp://lists.opensuse.org/opensuse-updates/2012-10/msg00013.htmlhttp://lists.opensuse.org/opensuse-updates/2012-10/msg00024.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1037.htmlhttp://secunia.com/advisories/49304http://secunia.com/advisories/50718http://security.freebsd.org/advisories/FreeBSD-SA-12:02.crypt.aschttp://support.apple.com/kb/HT5501http://www.debian.org/security/2012/dsa-2491http://www.mandriva.com/security/advisories?name=MDVSA-2012:092http://www.postgresql.org/docs/8.3/static/release-8-3-19.htmlhttp://www.postgresql.org/docs/8.4/static/release-8-4-12.htmlhttp://www.postgresql.org/docs/9.0/static/release-9-0-8.htmlhttp://www.postgresql.org/docs/9.1/static/release-9-1-4.htmlhttp://www.postgresql.org/support/security/http://www.securitytracker.com/id?1026995https://bugzilla.redhat.com/show_bug.cgi?id=816956
2012-07-05
Published