PHP Crypt Function Authentication Bypass Vulnerability
BID:24109
Info
PHP Crypt Function Authentication Bypass Vulnerability
| Bugtraq ID: | 24109 |
| Class: | Access Validation Error |
| CVE: |
CVE-2007-2844 |
| Remote: | Yes |
| Local: | No |
| Published: | May 22 2007 12:00AM |
| Updated: | May 07 2015 05:38PM |
| Credit: | Stefan Essar is credited with the discovery of this vulnerability. |
| Vulnerable: |
PHP PHP 5.2.2 PHP PHP 5.2.1 PHP PHP 5.1.6 PHP PHP 5.1.5 PHP PHP 5.1.4 PHP PHP 5.1.3 -RC1 PHP PHP 5.1.3 PHP PHP 5.1.2 PHP PHP 5.1.1 PHP PHP 5.1 PHP PHP 5.0.5 PHP PHP 5.0.4 PHP PHP 5.0.3 PHP PHP 5.0.2 PHP PHP 5.0.1 PHP PHP 5.0 candidate 3 PHP PHP 5.0 candidate 2 PHP PHP 5.0 candidate 1 PHP PHP 5.0 .0 PHP PHP 4.4.7 PHP PHP 4.4.6 PHP PHP 4.4.5 PHP PHP 4.4.4 PHP PHP 4.4.3 PHP PHP 4.4.2 PHP PHP 4.4.1 PHP PHP 4.4 .0 PHP PHP 4.3.11 PHP PHP 4.3.10 PHP PHP 4.3.9 PHP PHP 4.3.8 PHP PHP 4.3.7 PHP PHP 4.3.6 PHP PHP 4.3.5 PHP PHP 4.3.4 PHP PHP 4.3.3 PHP PHP 4.3.2 PHP PHP 4.3.1 PHP PHP 4.3 PHP PHP 4.2.3 PHP PHP 4.2.2 PHP PHP 4.2.1 PHP PHP 4.2 .0 PHP PHP 4.2 -dev PHP PHP 4.1.2 PHP PHP 4.1.1 PHP PHP 4.1 .0 PHP PHP 4.0.7 RC3 PHP PHP 4.0.7 RC2 PHP PHP 4.0.7 RC1 PHP PHP 4.0.7 PHP PHP 4.0.6 PHP PHP 4.0.5 PHP PHP 4.0.4 PHP PHP 4.0.3 pl1 PHP PHP 4.0.3 PHP PHP 4.0.2 PHP PHP 4.0.1 pl2 PHP PHP 4.0.1 pl1 PHP PHP 4.0.1 PHP PHP 5.2 |
| Not Vulnerable: | |
Discussion
PHP Crypt Function Authentication Bypass Vulnerability
PHP is prone to an authentication-bypass vulnerability that stems from a race condition in the 'crypt()' function.
An attacker could exploit the vulnerability in the 'crypt()' function to gain unauthorized access to an affected application.
PHP is prone to an authentication-bypass vulnerability that stems from a race condition in the 'crypt()' function.
An attacker could exploit the vulnerability in the 'crypt()' function to gain unauthorized access to an affected application.
Exploit / POC
PHP Crypt Function Authentication Bypass Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
PHP Crypt Function Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
PHP Crypt Function Authentication Bypass Vulnerability
References:
References:
- PHP Crypt Thread Safety Vulnerability (Stefan Essar )
- PHP Homepage (PHP)