Use of insecure channel - Source code In php53
Description
The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
rpm rhel6 | 0:8.4.12-1.el6_2 | ||
rpm rhel6 | 0:5.3.3-14.el6_3 | ||
rpm rhel5 | 0:5.3.3-13.el5_8 | ||
rpm rhel5 | 0:8.1.23-5.el5_8 | ||
rpm rhel5 | 0:8.4.12-1.el5_8 |
Aliases
1. 2. 3.