CVE-2012-2317
published 2012-08-07CVE-2012-2317: The Debian php_crypt_revamped.patch patch for PHP 5.3.x, as used in the php5 package before 5.3.3-7+squeeze4 in Debian GNU/Linux squeeze, the php5 package…
PriorityP428medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.46%
82.8th percentile
The Debian php_crypt_revamped.patch patch for PHP 5.3.x, as used in the php5 package before 5.3.3-7+squeeze4 in Debian GNU/Linux squeeze, the php5 package before 5.3.2-1ubuntu4.17 in Ubuntu 10.04 LTS, and the php5 package before 5.3.5-1ubuntu7.10 in Ubuntu 11.04, does not properly handle an empty salt string, which might allow remote attackers to bypass authentication by leveraging an application that relies on the PHP crypt function to choose a salt for password hashing.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | php5 | <= 5.3.2-1ubuntu4.16 | — |
| canonical | php5 | <= 5.3.5-1ubuntu7.9 | — |
| canonical | php5 | — | — |
| canonical | php5 | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | php5-common | <= 5.3.2-1 | — |
| debian | php5-common | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qcwp-wm5p-xc8j: The Debian php_crypt_revamped
ghsa_unreviewed·2022-05-17
CVE-2012-2317 [MEDIUM] GHSA-qcwp-wm5p-xc8j: The Debian php_crypt_revamped
The Debian php_crypt_revamped.patch patch for PHP 5.3.x, as used in the php5 package before 5.3.3-7+squeeze4 in Debian GNU/Linux squeeze, the php5 package before 5.3.2-1ubuntu4.17 in Ubuntu 10.04 LTS, and the php5 package before 5.3.5-1ubuntu7.10 in Ubuntu 11.04, does not properly handle an empty salt string, which might allow remote attackers to bypass authentication by leveraging an application that relies on the PHP crypt function to choose a salt for password hashing.
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2012-06-19·CVSS 5.0
CVE-2012-0781 [MEDIUM] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: Several security issues were fixed in PHP.
It was discovered that PHP incorrectly handled certain Tidy::diagnose
operations on invalid objects. A remote attacker could use this flaw to
cause PHP to crash, leading to a denial of service. (CVE-2012-0781)
It was discovered that PHP incorrectly handled certain multi-file upload
filenames. A remote attacker could use this flaw to cause a denial of
service, or to perform a directory traversal attack. (CVE-2012-1172)
Rubin Xu and Joseph Bonneau discovered that PHP incorrectly handled certain
Unicode characters in passwords passed to the crypt() function. A remote
attacker could possibly use this flaw to bypass authentication.
(CVE-2012-2143)
It was discovered that a Debian/Ubuntu specific patch caused PHP
No detection rules found.
No public exploits indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=581170http://www.openwall.com/lists/oss-security/2012/05/04/7http://www.openwall.com/lists/oss-security/2012/05/05/2http://www.ubuntu.com/usn/USN-1481-1http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=581170http://www.openwall.com/lists/oss-security/2012/05/04/7http://www.openwall.com/lists/oss-security/2012/05/05/2http://www.ubuntu.com/usn/USN-1481-1
2012-08-07
Published