CVE-2011-3189

Publication date 25 August 2011

Last updated 24 July 2024


Ubuntu priority

The crypt function in PHP 5.3.7, when the MD5 hash type is used, returns the value of the salt argument instead of the hashed string, which might allow remote attackers to bypass authentication via an arbitrary password, a different vulnerability than CVE-2011-2483.

Read the notes from the security team

Status

Package Ubuntu Release Status
php5 11.04 natty
Not affected
10.10 maverick
Not affected
10.04 LTS lucid
Not affected
8.04 LTS hardy
Not affected

Notes


jdstrand

regression CVE for php5 5.3.7