Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-2483

Опубликовано: 20 июн. 2011
Источник: redhat
CVSS2: 4.3

Описание

crypt_blowfish before 1.1, as used in PHP before 5.3.7 on certain platforms, PostgreSQL before 8.4.9, and other products, does not properly handle 8-bit characters, which makes it easier for context-dependent attackers to determine a cleartext password by leveraging knowledge of a password hash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 3rh-postgresqlWill not fix
Red Hat Enterprise Linux 4postgresqlFixedRHSA-2011:137717.10.2011
Red Hat Enterprise Linux 5postgresqlFixedRHSA-2011:137717.10.2011
Red Hat Enterprise Linux 5postgresql84FixedRHSA-2011:137817.10.2011
Red Hat Enterprise Linux 5php53FixedRHSA-2011:142302.11.2011
Red Hat Enterprise Linux 6postgresqlFixedRHSA-2011:137717.10.2011
Red Hat Enterprise Linux 6phpFixedRHSA-2011:142302.11.2011

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=715025crypt_blowfish: 8-bit character mishandling allows different password pairs to produce the same hash

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 14 лет назад

crypt_blowfish before 1.1, as used in PHP before 5.3.7 on certain platforms, PostgreSQL before 8.4.9, and other products, does not properly handle 8-bit characters, which makes it easier for context-dependent attackers to determine a cleartext password by leveraging knowledge of a password hash.

nvd
почти 14 лет назад

crypt_blowfish before 1.1, as used in PHP before 5.3.7 on certain platforms, PostgreSQL before 8.4.9, and other products, does not properly handle 8-bit characters, which makes it easier for context-dependent attackers to determine a cleartext password by leveraging knowledge of a password hash.

debian
почти 14 лет назад

crypt_blowfish before 1.1, as used in PHP before 5.3.7 on certain plat ...

github
около 3 лет назад

crypt_blowfish before 1.1, as used in PHP before 5.3.7 on certain platforms, PostgreSQL before 8.4.9, and other products, does not properly handle 8-bit characters, which makes it easier for context-dependent attackers to determine a cleartext password by leveraging knowledge of a password hash.

oracle-oval
больше 13 лет назад

ELSA-2011-1378: postgresql84 security update (MODERATE)

4.3 Medium

CVSS2