cbcvebase.
CVE-2012-2317
published 2012-08-07

CVE-2012-2317: The Debian php_crypt_revamped.patch patch for PHP 5.3.x, as used in the php5 package before 5.3.3-7+squeeze4 in Debian GNU/Linux squeeze, the php5 package…

PriorityP428medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.46%
82.8th percentile
The Debian php_crypt_revamped.patch patch for PHP 5.3.x, as used in the php5 package before 5.3.3-7+squeeze4 in Debian GNU/Linux squeeze, the php5 package before 5.3.2-1ubuntu4.17 in Ubuntu 10.04 LTS, and the php5 package before 5.3.5-1ubuntu7.10 in Ubuntu 11.04, does not properly handle an empty salt string, which might allow remote attackers to bypass authentication by leveraging an application that relies on the PHP crypt function to choose a salt for password hashing.

Affected

8 ranges
VendorProductVersion rangeFixed in
canonicalphp5<= 5.3.2-1ubuntu4.16
canonicalphp5<= 5.3.5-1ubuntu7.9
canonicalphp5
canonicalphp5
canonicalubuntu_linux
canonicalubuntu_linux
debianphp5-common<= 5.3.2-1
debianphp5-common

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.