{"api_version":"1","generated_at":"2026-07-23T08:24:03+00:00","cve":"CVE-2012-2143","urls":{"html":"https://cve.report/CVE-2012-2143","api":"https://cve.report/api/cve/CVE-2012-2143.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2012-2143","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2012-2143"},"summary":{"title":"CVE-2012-2143","description":"The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.","state":"PUBLISHED","assigner":"redhat","published_at":"2012-07-05 14:55:02","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-310","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://rhn.redhat.com/errata/RHSA-2012-1037.html","name":"http://rhn.redhat.com/errata/RHSA-2012-1037.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1026995","name":"http://www.securitytracker.com/id?1026995","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"FreeBSD crypt(3) Hash Generation Error May Generate Incorrect Hashes - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.postgresql.org/docs/9.1/static/release-9-1-4.html","name":"http://www.postgresql.org/docs/9.1/static/release-9-1-4.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"PostgreSQL: Documentation: 9.1: Release 9.1.4","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://security.freebsd.org/advisories/FreeBSD-SA-12:02.crypt.asc","name":"http://security.freebsd.org/advisories/FreeBSD-SA-12:02.crypt.asc","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00003.html","name":"http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00003.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[security-announce] SUSE-SU-2012:0840-1: important: Security update for","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=aab49e934de1fff046e659cbec46e3d053b41c34","name":"http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=aab49e934de1fff046e659cbec46e3d053b41c34","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Patch"],"title":"208.43.231.11 Git - php-src.git/commit","mime":"text/xml","httpstatus":"-1","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-updates/2012-10/msg00024.html","name":"http://lists.opensuse.org/opensuse-updates/2012-10/msg00024.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"openSUSE-SU-2012:1299-1: moderate: postgresql: security and bugfix upgra","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2012/dsa-2491","name":"http://www.debian.org/security/2012/dsa-2491","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian -- Security Information -- DSA-2491-1 postgresql-8.4","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082258.html","name":"http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082258.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[SECURITY] Fedora 16 Update: postgresql-9.1.4-1.fc16","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082292.html","name":"http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082292.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[SECURITY] Fedora 17 Update: postgresql-9.1.4-1.fc17","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.apple.com/kb/HT5501","name":"http://support.apple.com/kb/HT5501","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"About the security content of OS X Mountain Lion v10.8.2, OS X Lion v10.7.5 and Security Update 2012-004","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2012:092","name":"http://www.mandriva.com/security/advisories?name=MDVSA-2012:092","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Support / Security / Advisories /  / MDVSA-2012:092 | Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.postgresql.org/support/security/","name":"http://www.postgresql.org/support/security/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"PostgreSQL: Security Information","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.postgresql.org/docs/9.0/static/release-9-0-8.html","name":"http://www.postgresql.org/docs/9.0/static/release-9-0-8.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"PostgreSQL: Documentation: 9.0: Release 9.0.8","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=816956","name":"https://bugzilla.redhat.com/show_bug.cgi?id=816956","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Third Party Advisory"],"title":"Bug 816956 – CVE-2012-2143 BSD crypt(): DES encrypted password weakness","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.postgresql.org/docs/8.4/static/release-8-4-12.html","name":"http://www.postgresql.org/docs/8.4/static/release-8-4-12.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"PostgreSQL: Documentation: 8.4: Release 8.4.12","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/49304","name":"http://secunia.com/advisories/49304","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"About Secunia Research | Flexera","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-updates/2012-09/msg00102.html","name":"http://lists.opensuse.org/opensuse-updates/2012-09/msg00102.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"openSUSE-SU-2012:1251-1: moderate: postgresql, postgresql-libs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/50718","name":"http://secunia.com/advisories/50718","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Security Advisory SA50718 - SUSE update for postgresql and postgresql-libs - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082294.html","name":"http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082294.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[SECURITY] Fedora 15 Update: postgresql-9.0.8-1.fc15","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-updates/2012-10/msg00013.html","name":"http://lists.opensuse.org/opensuse-updates/2012-10/msg00013.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"openSUSE-SU-2012:1288-1: moderate: postgresql, postgresql-libs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://git.postgresql.org/gitweb/?p=postgresql.git&a=commit&h=932ded2ed51e8333852e370c7a6dad75d9f236f9","name":"http://git.postgresql.org/gitweb/?p=postgresql.git&a=commit&h=932ded2ed51e8333852e370c7a6dad75d9f236f9","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"git.postgresql.org Git - postgresql.git/commit","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://www.postgresql.org/docs/8.3/static/release-8-3-19.html","name":"http://www.postgresql.org/docs/8.3/static/release-8-3-19.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"PostgreSQL: Documentation: 8.3: Release 8.3.19","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705","name":"http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Juniper Networks - 2015-10 Security Bulletin: CTPView: Multiple Vulnerabilities in CTPView","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html","name":"http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"APPLE-SA-2012-09-19-2 OS X Mountain Lion v10.8.2,\tOS X Lion v10.7.5 and Security Update 2012-004","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://git.php.net/?p=php-src.git;a=commit;h=aab49e934de1fff046e659cbec46e3d053b41c34","name":"CONFIRM:http://git.php.net/?p=php-src.git;a=commit;h=aab49e934de1fff046e659cbec46e3d053b41c34","refsource":"MITRE","tags":[],"title":"208.43.231.11 Git - php-src.git/commit","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2012-2143","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2012-2143","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2012","cve_id":"2143","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"postgresql","cpe5":"postgresql","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T19:26:08.919Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.postgresql.org/docs/9.1/static/release-9-1-4.html"},{"name":"SUSE-SU-2012:0840","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00003.html"},{"name":"FreeBSD-SA-12:02","tags":["vendor-advisory","x_refsource_FREEBSD","x_transferred"],"url":"http://security.freebsd.org/advisories/FreeBSD-SA-12:02.crypt.asc"},{"name":"50718","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/50718"},{"name":"FEDORA-2012-8924","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082292.html"},{"name":"FEDORA-2012-8893","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082258.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=816956"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.postgresql.org/support/security/"},{"name":"DSA-2491","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2012/dsa-2491"},{"name":"1026995","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1026995"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=aab49e934de1fff046e659cbec46e3d053b41c34"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.postgresql.org/docs/8.3/static/release-8-3-19.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.postgresql.org/docs/8.4/static/release-8-4-12.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://git.postgresql.org/gitweb/?p=postgresql.git&a=commit&h=932ded2ed51e8333852e370c7a6dad75d9f236f9"},{"name":"APPLE-SA-2012-09-19-2","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.apple.com/kb/HT5501"},{"name":"RHSA-2012:1037","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2012-1037.html"},{"name":"FEDORA-2012-8915","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082294.html"},{"name":"MDVSA-2012:092","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2012:092"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.postgresql.org/docs/9.0/static/release-9-0-8.html"},{"name":"openSUSE-SU-2012:1251","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-updates/2012-09/msg00102.html"},{"name":"openSUSE-SU-2012:1288","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-updates/2012-10/msg00013.html"},{"name":"49304","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/49304"},{"name":"openSUSE-SU-2012:1299","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-updates/2012-10/msg00024.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2012-05-30T00:00:00.000Z","descriptions":[{"lang":"en","value":"The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-12-06T18:57:01.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.postgresql.org/docs/9.1/static/release-9-1-4.html"},{"name":"SUSE-SU-2012:0840","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00003.html"},{"name":"FreeBSD-SA-12:02","tags":["vendor-advisory","x_refsource_FREEBSD"],"url":"http://security.freebsd.org/advisories/FreeBSD-SA-12:02.crypt.asc"},{"name":"50718","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/50718"},{"name":"FEDORA-2012-8924","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082292.html"},{"name":"FEDORA-2012-8893","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082258.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=816956"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.postgresql.org/support/security/"},{"name":"DSA-2491","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2012/dsa-2491"},{"name":"1026995","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1026995"},{"tags":["x_refsource_CONFIRM"],"url":"http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=aab49e934de1fff046e659cbec46e3d053b41c34"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.postgresql.org/docs/8.3/static/release-8-3-19.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.postgresql.org/docs/8.4/static/release-8-4-12.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://git.postgresql.org/gitweb/?p=postgresql.git&a=commit&h=932ded2ed51e8333852e370c7a6dad75d9f236f9"},{"name":"APPLE-SA-2012-09-19-2","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.apple.com/kb/HT5501"},{"name":"RHSA-2012:1037","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2012-1037.html"},{"name":"FEDORA-2012-8915","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082294.html"},{"name":"MDVSA-2012:092","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2012:092"},{"tags":["x_refsource_CONFIRM"],"url":"http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.postgresql.org/docs/9.0/static/release-9-0-8.html"},{"name":"openSUSE-SU-2012:1251","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-updates/2012-09/msg00102.html"},{"name":"openSUSE-SU-2012:1288","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-updates/2012-10/msg00013.html"},{"name":"49304","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/49304"},{"name":"openSUSE-SU-2012:1299","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-updates/2012-10/msg00024.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2012-2143","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.postgresql.org/docs/9.1/static/release-9-1-4.html","refsource":"CONFIRM","url":"http://www.postgresql.org/docs/9.1/static/release-9-1-4.html"},{"name":"SUSE-SU-2012:0840","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00003.html"},{"name":"FreeBSD-SA-12:02","refsource":"FREEBSD","url":"http://security.freebsd.org/advisories/FreeBSD-SA-12:02.crypt.asc"},{"name":"50718","refsource":"SECUNIA","url":"http://secunia.com/advisories/50718"},{"name":"FEDORA-2012-8924","refsource":"FEDORA","url":"http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082292.html"},{"name":"FEDORA-2012-8893","refsource":"FEDORA","url":"http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082258.html"},{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=816956","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/show_bug.cgi?id=816956"},{"name":"http://www.postgresql.org/support/security/","refsource":"CONFIRM","url":"http://www.postgresql.org/support/security/"},{"name":"DSA-2491","refsource":"DEBIAN","url":"http://www.debian.org/security/2012/dsa-2491"},{"name":"1026995","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1026995"},{"name":"http://git.php.net/?p=php-src.git;a=commit;h=aab49e934de1fff046e659cbec46e3d053b41c34","refsource":"CONFIRM","url":"http://git.php.net/?p=php-src.git;a=commit;h=aab49e934de1fff046e659cbec46e3d053b41c34"},{"name":"http://www.postgresql.org/docs/8.3/static/release-8-3-19.html","refsource":"CONFIRM","url":"http://www.postgresql.org/docs/8.3/static/release-8-3-19.html"},{"name":"http://www.postgresql.org/docs/8.4/static/release-8-4-12.html","refsource":"CONFIRM","url":"http://www.postgresql.org/docs/8.4/static/release-8-4-12.html"},{"name":"http://git.postgresql.org/gitweb/?p=postgresql.git&a=commit&h=932ded2ed51e8333852e370c7a6dad75d9f236f9","refsource":"CONFIRM","url":"http://git.postgresql.org/gitweb/?p=postgresql.git&a=commit&h=932ded2ed51e8333852e370c7a6dad75d9f236f9"},{"name":"APPLE-SA-2012-09-19-2","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html"},{"name":"http://support.apple.com/kb/HT5501","refsource":"CONFIRM","url":"http://support.apple.com/kb/HT5501"},{"name":"RHSA-2012:1037","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2012-1037.html"},{"name":"FEDORA-2012-8915","refsource":"FEDORA","url":"http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082294.html"},{"name":"MDVSA-2012:092","refsource":"MANDRIVA","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2012:092"},{"name":"http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705","refsource":"CONFIRM","url":"http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705"},{"name":"http://www.postgresql.org/docs/9.0/static/release-9-0-8.html","refsource":"CONFIRM","url":"http://www.postgresql.org/docs/9.0/static/release-9-0-8.html"},{"name":"openSUSE-SU-2012:1251","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-updates/2012-09/msg00102.html"},{"name":"openSUSE-SU-2012:1288","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-updates/2012-10/msg00013.html"},{"name":"49304","refsource":"SECUNIA","url":"http://secunia.com/advisories/49304"},{"name":"openSUSE-SU-2012:1299","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-updates/2012-10/msg00024.html"}]}}}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2012-2143","datePublished":"2012-07-05T14:00:00.000Z","dateReserved":"2012-04-04T00:00:00.000Z","dateUpdated":"2024-08-06T19:26:08.919Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2012-07-05 14:55:02","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-310","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*","versionStartIncluding":"8.3","versionEndExcluding":"8.3.19","matchCriteriaId":"B0883209-4A15-421B-A7B9-6EA5C51BA2E4"},{"vulnerable":true,"criteria":"cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*","versionStartIncluding":"8.4","versionEndExcluding":"8.4.12","matchCriteriaId":"B0D785B1-6406-422D-9962-A41EE5724A72"},{"vulnerable":true,"criteria":"cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*","versionStartIncluding":"9.0","versionEndExcluding":"9.0.8","matchCriteriaId":"82089569-18FD-40EB-9EB4-009223F1A535"},{"vulnerable":true,"criteria":"cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*","versionStartIncluding":"9.1","versionEndExcluding":"9.1.4","matchCriteriaId":"193C7F88-26DE-4D6B-ABC9-F79491464143"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*","versionEndIncluding":"9.0","matchCriteriaId":"2F7B2CC9-2907-49AF-8497-CE60554123F4"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:1.0:*:*:*:*:*:*:*","matchCriteriaId":"44EFD22E-02C9-4B80-8934-A9AC8DD858CF"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:1.1:*:*:*:*:*:*:*","matchCriteriaId":"B1B4D4A5-25EB-48FE-BDFD-A274CE802648"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:1.1.5:*:*:*:*:*:*:*","matchCriteriaId":"C11DD743-A21D-48F4-BD55-A8A4FA960F94"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:1.1.5.1:*:*:*:*:*:*:*","matchCriteriaId":"C496B665-70DA-4B98-A5D1-E2935C0CE840"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:2.0:*:*:*:*:*:*:*","matchCriteriaId":"F1F098C1-D09E-49B4-9B51-E84B6C4EA6CD"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:2.0.5:*:*:*:*:*:*:*","matchCriteriaId":"34797660-41F5-4358-B70F-2A40DE48F182"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:2.1:*:*:*:*:*:*:*","matchCriteriaId":"6B3A2EBB-0359-49A7-B7F9-56EE6FD85D29"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:2.1.5:*:*:*:*:*:*:*","matchCriteriaId":"4054D69F-596F-4EB4-BE9A-E2478343F55A"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:2.1.6:*:*:*:*:*:*:*","matchCriteriaId":"CA26ABBE-9973-45FA-9E9B-82170B751219"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:2.1.7:*:*:*:*:*:*:*","matchCriteriaId":"CF4F7002-A525-4A66-BE8B-E50ABBF144B2"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:2.2:*:*:*:*:*:*:*","matchCriteriaId":"183667CA-6DF1-4BFB-AE32-9ABF55B7283A"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:2.2.1:*:*:*:*:*:*:*","matchCriteriaId":"F1156954-25AD-45BE-AE49-9705ECD5BDA2"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:2.2.2:*:*:*:*:*:*:*","matchCriteriaId":"EBDDEC3F-52EB-4E1E-84C4-B472600059EC"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:2.2.5:*:*:*:*:*:*:*","matchCriteriaId":"314BA420-4C74-4060-8ACE-D7A7C041CF2B"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:2.2.6:*:*:*:*:*:*:*","matchCriteriaId":"2EAD7613-A5B3-4621-B981-290C7C6B8BA0"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:2.2.7:*:*:*:*:*:*:*","matchCriteriaId":"8ED84E66-CFD9-4DF8-9679-13457D340D54"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:2.2.8:*:*:*:*:*:*:*","matchCriteriaId":"D1CA3337-9BEE-49C5-9EDE-8CDBE5580537"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:3.0:*:*:*:*:*:*:*","matchCriteriaId":"EE38C50A-81FE-412E-9717-3672FAE6A6F4"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:3.1:*:*:*:*:*:*:*","matchCriteriaId":"263F3734-7076-4EA8-B4C0-F37CFC4E979E"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:3.2:*:*:*:*:*:*:*","matchCriteriaId":"0419DD66-FF66-48BC-AD3B-F6AFD0551E36"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:3.3:*:*:*:*:*:*:*","matchCriteriaId":"C3518628-08E5-4AD7-AAF6-A4E38F1CDE2C"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:3.4:*:*:*:*:*:*:*","matchCriteriaId":"B982342C-1981-4C55-8044-AFE4D87623DF"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:3.5:*:*:*:*:*:*:*","matchCriteriaId":"47E02BE6-4800-4940-B269-385B66AC5077"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:4.0:*:*:*:*:*:*:*","matchCriteriaId":"D0A585A1-FF82-418F-90F8-072458DB7816"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:4.1:*:*:*:*:*:*:*","matchCriteriaId":"AE31DFF8-06AB-489D-A0C5-509C090283B5"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:4.1.1:*:*:*:*:*:*:*","matchCriteriaId":"3BE1E3D8-2BB1-4FFA-9BC9-7AF347D26190"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:4.2:*:*:*:*:*:*:*","matchCriteriaId":"DF49BF03-C25E-4737-84D5-892895C86C58"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:4.3:*:*:*:*:*:*:*","matchCriteriaId":"D2019E0E-426B-43AF-8904-1B811AE171E8"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:4.4:*:*:*:*:*:*:*","matchCriteriaId":"55C5FC1A-1253-4390-A4FC-573BB14EA937"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:4.5:*:*:*:*:*:*:*","matchCriteriaId":"44308D13-D935-4FF8-AB52-F0E115ED1AD2"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:4.6:*:*:*:*:*:*:*","matchCriteriaId":"9C001822-FDF8-497C-AC2C-B59A00E9ACD2"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:4.6.2:*:*:*:*:*:*:*","matchCriteriaId":"4AB4AD26-6AF2-4F3A-B602-F231FAABA73E"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:4.7:*:*:*:*:*:*:*","matchCriteriaId":"B86C77AB-B8FF-4376-9B4E-C88417396F3D"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:4.8:*:*:*:*:*:*:*","matchCriteriaId":"441BE3A0-20F4-4972-B279-19B3DB5FA14D"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:4.9:*:*:*:*:*:*:*","matchCriteriaId":"00EAEA17-033A-4A50-8E39-D61154876D2F"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:4.10:*:*:*:*:*:*:*","matchCriteriaId":"9FFD9D1C-A459-47AD-BC62-15631417A32F"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:4.11:*:*:*:*:*:*:*","matchCriteriaId":"582B9BF3-5BF1-44A3-A580-62F2D44FDD34"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:5.0:*:*:*:*:*:*:*","matchCriteriaId":"61EBA52A-2D8B-4FB5-866E-AE67CE1842E7"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:5.1:*:*:*:*:*:*:*","matchCriteriaId":"4EE93350-92E6-4F5C-A14C-9993CFFDBCD4"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:5.2:*:*:*:*:*:*:*","matchCriteriaId":"DD7C441E-444B-4DF5-8491-86805C70FB99"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:5.2.1:*:*:*:*:*:*:*","matchCriteriaId":"BAD73CDB-94C5-4DBF-8B4C-DD3E4E399445"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:5.3:*:*:*:*:*:*:*","matchCriteriaId":"D8A80E6A-6502-4A33-83BA-7DCC606D79AA"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:5.4:*:*:*:*:*:*:*","matchCriteriaId":"AD85B1ED-1473-4C22-9E1E-53F07CF517E9"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:5.5:*:*:*:*:*:*:*","matchCriteriaId":"7752D43D-64AF-474F-BFBB-2625A29C1B88"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:6.0:*:*:*:*:*:*:*","matchCriteriaId":"1D2C79D5-D27F-4B08-A8DF-3E3AAF4E16A5"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:6.1:*:*:*:*:*:*:*","matchCriteriaId":"F4416CBA-76B9-4051-B015-F1BE89517309"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:6.2:*:*:*:*:*:*:*","matchCriteriaId":"9118B602-3FB6-4701-AC09-763DD48334BA"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:6.3:*:*:*:*:*:*:*","matchCriteriaId":"F702C46F-CA02-4FA2-B7D6-C61C2C095679"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:6.4:*:*:*:*:*:*:*","matchCriteriaId":"A4F7F02A-C845-40BF-8490-510A070000F3"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:7.0:*:*:*:*:*:*:*","matchCriteriaId":"47E0A416-733A-4616-AE08-150D67FCEA70"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:7.1:*:*:*:*:*:*:*","matchCriteriaId":"803EFA9F-B7CB-4511-B1C1-381170CA9A23"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:7.2:*:*:*:*:*:*:*","matchCriteriaId":"F948527C-A01E-4315-80B6-47FACE18A34F"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:7.3:*:*:*:*:*:*:*","matchCriteriaId":"1F25FB59-1E4F-4420-8482-8007FF5E2411"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:7.4:*:*:*:*:*:*:*","matchCriteriaId":"0C94B745-BD27-423D-BBB6-A821CD9BC1C4"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:8.0:*:*:*:*:*:*:*","matchCriteriaId":"3CF1F9EF-01AF-4708-AE02-765360AF3D66"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:8.1:*:*:*:*:*:*:*","matchCriteriaId":"9899C87E-2C09-46AE-BC24-1ACF012784CA"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:8.2:*:*:*:*:*:*:*","matchCriteriaId":"DD5ECA1A-D9B4-4ED7-95EC-684E7AA2B765"},{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:8.3:*:*:*:*:*:*:*","matchCriteriaId":"30C501A1-FE2D-41E7-A5DB-C61D8701B9B4"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","versionEndExcluding":"5.3.14","matchCriteriaId":"4771E65B-4C4C-4299-B6DB-E7B35233C63C"},{"vulnerable":true,"criteria":"cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4.0","versionEndExcluding":"5.4.4","matchCriteriaId":"64C21940-9DA6-4922-B43E-4EA79FD918C1"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*","matchCriteriaId":"036E8A89-7A16-411F-9D31-676313BB7244"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2012","CveId":"2143","Ordinal":"1","Title":"CVE-2012-2143","CVE":"CVE-2012-2143","Year":"2012"},"notes":[{"CveYear":"2012","CveId":"2143","Ordinal":"1","NoteData":"The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.","Type":"Description","Title":"CVE-2012-2143"},{"CveYear":"2012","CveId":"2143","Ordinal":"2","NoteData":"2012-07-05","Type":"Other","Title":"Published"},{"CveYear":"2012","CveId":"2143","Ordinal":"3","NoteData":"2016-12-06","Type":"Other","Title":"Modified"}]}}}