MEDIUM · 4.3

CVE-2012-2143

The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contain...

Vulnerability Description

The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
PostgresqlPostgresql>= 8.3, < 8.3.19
FreebsdFreebsd<= 9.0
PhpPhp< 5.3.14
DebianDebian Linux6.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-2143?

CVE-2012-2143 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contain...

How severe is CVE-2012-2143?

CVE-2012-2143 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-2143?

Check the references section above for vendor advisories and patch information. Affected products include: Postgresql Postgresql, Freebsd Freebsd, Php Php, Debian Debian Linux.