REDHAT-BUG-2170771: Low severity php vulnerability
CVE-2023-0567[0]: PHP: Passwordverify() always return true with some hash
[0] https://security-tracker.debian.org/tracker/CVE-2023-0567 https://www.cve.org/CVERecord?id=CVE-2023-0567 https://github.com/php/php-src/security/advisories/GHSA-7fj2-8x79-rjf4
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2170771?
The severity of REDHAT-BUG-2170771 is considered high due to the potential for password verification failures.
How do I fix REDHAT-BUG-2170771?
To fix REDHAT-BUG-2170771, update to the latest stable version of PHP that addresses CVE-2023-0567.
What systems are affected by REDHAT-BUG-2170771?
REDHAT-BUG-2170771 affects PHP installations that utilize the Password_verify() function for password validation.
What are the implications of REDHAT-BUG-2170771?
The implications of REDHAT-BUG-2170771 include the risk of unauthorized access due to incorrect password verification.
Is there a workaround for REDHAT-BUG-2170771?
A temporary workaround for REDHAT-BUG-2170771 may involve using alternative password hashing methods until the software is updated.