Debian 'php_crypt_revamped.patch' Patch Security Bypass Vulnerability
BID:54875
Info
Debian 'php_crypt_revamped.patch' Patch Security Bypass Vulnerability
| Bugtraq ID: | 54875 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-2317 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 07 2012 12:00AM |
| Updated: | Aug 07 2012 12:00AM |
| Credit: | Boaz Rymland |
| Vulnerable: |
Ubuntu Ubuntu Linux 11.04 Ubuntu Ubuntu Linux 10.04 LTS Debian Linux 6.0.5 |
| Not Vulnerable: | |
Discussion
Debian 'php_crypt_revamped.patch' Patch Security Bypass Vulnerability
The Debian patch for PHP is prone to a security-bypass vulnerability.
Successful exploits will allow an attackers to bypass certain security restrictions.
The Debian patch for PHP is prone to a security-bypass vulnerability.
Successful exploits will allow an attackers to bypass certain security restrictions.
Solution / Fix
Debian 'php_crypt_revamped.patch' Patch Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Debian 'php_crypt_revamped.patch' Patch Security Bypass Vulnerability
References:
References:
- Debian/Ubuntu php_crypt_revamped.patch (oss-security)
- PHP Homepage (PHP)
- php5 crypt() does not complete with emtpy salt (Debian)
- Vulnerability Summary for CVE-2012-2317 (NIST)
- USN-1481-1: PHP vulnerabilities (Ubuntu)