First published: Tue Feb 14 2023(Updated: )
<a href="https://access.redhat.com/security/cve/CVE-2023-0567">CVE-2023-0567</a>[0]: PHP: Password_verify() always return true with some hash [0] <a href="https://security-tracker.debian.org/tracker/CVE-2023-0567">https://security-tracker.debian.org/tracker/CVE-2023-0567</a> <a href="https://www.cve.org/CVERecord?id=CVE-2023-0567">https://www.cve.org/CVERecord?id=CVE-2023-0567</a> <a href="https://github.com/php/php-src/security/advisories/GHSA-7fj2-8x79-rjf4">https://github.com/php/php-src/security/advisories/GHSA-7fj2-8x79-rjf4</a>
Credit: security@php.net security@php.net security@php.net
Affected Software | Affected Version | How to fix |
---|---|---|
debian/php7.4 | 7.4.33-1+deb11u5 7.4.33-1+deb11u7 | |
debian/php8.2 | 8.2.26-1~deb12u1 8.2.27-1 | |
PHP | >=8.0.0<8.0.28 | |
PHP | >=8.1.0<8.1.16 | |
PHP | >=8.2.0<8.2.3 | |
PHP | <8.2.3 | 8.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this bug is CVE-2023-0567.
The title of this bug is Fixed bug (Password_verify() always return true with some hash).
The affected software is PHP 8.2.3.
The severity of this vulnerability is not mentioned.
The vulnerability can be fixed by updating PHP to version 8.2.3.