The crypt function in PHP 5.3.7, when the MD5 hash type is used, returns the value of the salt argument instead of the hashed string, which might allow remote attackers to bypass authentication via an arbitrary password, a different vulnerability than CVE-2011-2483.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Addressbook | — | Apply OS X security update 2012-001Upgrade macOS to the latest version | Aug 28, 2015 | Aug 25, 2011 |
| Apple Osx Php | — | Upgrade macOS to the latest versionApply OS X security update 2012-001 | Feb 3, 2012 | Aug 25, 2011 |
| Gentoo Linux | — | Upgrade dev-lang/php. | Oct 30, 2017 | Aug 25, 2011 |
| Hpsmh | — | Upgrade to the latest version of HP System Management Homepage | Oct 13, 2015 | Aug 25, 2011 |
| Php | — | Upgrade to PHP version 5.3.8 | Oct 1, 2012 | Aug 25, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub