CVE-2012-2317: Medium severity Debian Php5-common vulnerability
The Debian phpcryptrevamped.patch patch for PHP 5.3.x, as used in the php5 package before 5.3.3-7+squeeze4 in Debian GNU/Linux squeeze, the php5 package before 5.3.2-1ubuntu4.17 in Ubuntu 10.04 LTS, and the php5 package before 5.3.5-1ubuntu7.10 in Ubuntu 11.04, does not properly handle an empty salt string, which might allow remote attackers to bypass authentication by leveraging an application that relies on the PHP crypt function to choose a salt for password hashing.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2317?
CVE-2012-2317 has a medium severity rating due to its potential to lead to unexpected behavior in the affected PHP versions.
How do I fix CVE-2012-2317?
To fix CVE-2012-2317, you should upgrade to the latest patched versions of PHP 5.3.x provided by your distribution.
Which PHP versions are affected by CVE-2012-2317?
CVE-2012-2317 affects PHP 5.3.x versions prior to 5.3.3-7+squeeze4 in Debian and PHP 5.3.2-1ubuntu4.17 in Ubuntu.
Is there a workaround for CVE-2012-2317?
There is no official workaround for CVE-2012-2317; the best course of action is to apply the software update.
Should I be concerned about CVE-2012-2317 in my applications?
Yes, if your applications depend on the affected versions of PHP, they may be vulnerable to exploits exploiting this issue.