CVE Vulnerabilities

CVE-2012-2143

Published: Jul 05, 2012 | Modified: Mar 14, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.

Affected Software

Name Vendor Start Version End Version
Postgresql Postgresql 8.3 (including) 8.3.19 (excluding)
Postgresql Postgresql 8.4 (including) 8.4.12 (excluding)
Postgresql Postgresql 9.0 (including) 9.0.8 (excluding)
Postgresql Postgresql 9.1 (including) 9.1.4 (excluding)

References