CVE-2012-2317 describes a vulnerability in the Debian php_crypt_revamped.patch for PHP 5.3.x, affecting specific versions of PHP 5 in Debian GNU/Linux squeeze and Ubuntu 10.04 LTS and 11.04. The flaw stems from improper handling of an empty salt string by the PHP crypt function, potentially allowing remote attackers to bypass authentication in applications that rely on this function to generate a salt for password hashing. The vulnerability has a CVSS score of 4.3, indicating a medium severity. It is remotely exploitable with medium attack complexity and could lead to partial integrity compromise (bypassing authentication) without requiring authentication. There is no evidence of active exploitation, nor are there known exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness and attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.3.2-1CPE matchmatch criteria | cpe:2.3:a:debian:php5-common:*:*:*:*:*:*:*:* | ||
5.3.3-7\+squeeze4CPE matchmatch criteria | cpe:2.3:a:debian:php5-common:5.3.3-7\+squeeze4:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:*:*:*:*:*:*:*:* | ||
<= 5.3.2-1ubuntu4.16CPE matchmatch criteria | cpe:2.3:a:canonical:php5:*:*:*:*:*:*:*:* | ||
5.3.2-1ubuntu4.17CPE matchmatch criteria | cpe:2.3:a:canonical:php5:5.3.2-1ubuntu4.17:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.