CVE-2011-2483

crypt_blowfish before 1.1, as used in PHP before 5.3.7 on certain platforms, PostgreSQL before 8.4.9, and other products, does not proper… (CVE-2011-2483)

Description

crypt_blowfish before 1.1, as used in PHP before 5.3.7 on certain platforms, PostgreSQL before 8.4.9, and other products, does not properly handle 8-bit characters, which makes it easier for context-dependent attackers to determine a cleartext password by leveraging knowledge of a password hash.

Source: CVELISTV5NVD

Metrics

Severity
none
no public PoC known
91.7 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
5.0 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2011-08-25 14:00 UTC

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • openwall

    crypt_blowfish1.1

  • php

    php5.3.7

  • postgresql

    postgresql8.2.0 – 8.2.22

  • postgresql

    postgresql8.3.0 – 8.3.16

  • postgresql

    postgresql8.4.0 – 8.4.9

  • postgresql

    postgresql9.0.0 – 9.0.5

References & sources

IDCVE-2011-2483