---
title: "CVE-2012-2317\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2012-2317?format=md
keywords: index, follow
---

# CVE-2012-2317

Publication date 14 May 2012

Last updated 24 July 2024

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The Debian php\_crypt\_revamped.patch patch for PHP 5.3.x, as used in the
php5 package before 5.3.3-7+squeeze4 in Debian GNU/Linux squeeze, the php5
package before 5.3.2-1ubuntu4.17 in Ubuntu 10.04 LTS, and the php5 package
before 5.3.5-1ubuntu7.10 in Ubuntu 11.04, does not properly handle an empty
salt string, which might allow remote attackers to bypass authentication by
leveraging an application that relies on the PHP crypt function to choose a
salt for password hashing.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2012-2317?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| php5 | 12.04 LTS precise | Not affected |
| 11.10 oneiric | Not affected |
| 11.04 natty | Fixed 5.3.5-1ubuntu7.10 |
| 10.04 LTS lucid | Fixed 5.3.2-1ubuntu4.17 |
| 8.04 LTS hardy | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2012-2317?format=md#patch-details)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

introduced in php\_crypt\_revamped.patch patch in 5.3.2-1
reproducer in debian bug
also fixed in 5.3.3-7+squeeze4

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| php5 | * Vendor:   <http://anonscm.debian.org/gitweb/?p=pkg-php/php.git;a=commit;h=67c8dbacdc336c93fa84bb1d76a790704c296fec> |

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2317)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2012-2317)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2012-2317)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2012-2317)

### Related Ubuntu Security Notices (USN)

+ [USN-1481-1](https://usn.ubuntu.com/USN-1481-1)
+ PHP vulnerabilities
+ 19 June 2012

### Other references

* <http://www.openwall.com/lists/oss-security/2012/05/04/7>
* <https://www.cve.org/CVERecord?id=CVE-2012-2317>
