CVE-2012-2143
Publication date 5 June 2012
Last updated 24 July 2024
Ubuntu priority
The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.
Status
Package | Ubuntu Release | Status |
---|---|---|
php5 | 13.04 raring |
Not affected
|
12.10 quantal |
Not affected
|
|
12.04 LTS precise |
Fixed 5.3.10-1ubuntu3.2
|
|
11.10 oneiric |
Fixed 5.3.6-13ubuntu3.8
|
|
11.04 natty |
Fixed 5.3.5-1ubuntu7.10
|
|
10.10 maverick | Ignored end of life | |
10.04 LTS lucid |
Fixed 5.3.2-1ubuntu4.17
|
|
8.04 LTS hardy |
Not affected
|
|
postgresql-8.2 | 13.04 raring | Not in release |
12.10 quantal | Not in release | |
12.04 LTS precise | Not in release | |
11.10 oneiric | Not in release | |
11.04 natty | Not in release | |
10.04 LTS lucid | Not in release | |
8.04 LTS hardy | Ignored end of life | |
postgresql-8.3 | 13.04 raring | Not in release |
12.10 quantal | Not in release | |
12.04 LTS precise | Not in release | |
11.10 oneiric | Not in release | |
11.04 natty | Not in release | |
10.04 LTS lucid | Not in release | |
8.04 LTS hardy |
Fixed 8.3.19-0ubuntu8.04
|
|
postgresql-8.4 | 13.04 raring | Not in release |
12.10 quantal | Not in release | |
12.04 LTS precise |
Fixed 8.4.17-0ubuntu12.04
|
|
11.10 oneiric | Ignored end of life | |
11.04 natty |
Fixed 8.4.12-0ubuntu11.04
|
|
10.04 LTS lucid |
Fixed 8.4.12-0ubuntu10.04
|
|
8.04 LTS hardy | Not in release | |
postgresql-9.1 | 13.04 raring |
Not affected
|
12.10 quantal |
Not affected
|
|
12.04 LTS precise |
Fixed 9.1.4-0ubuntu12.04
|
|
11.10 oneiric |
Fixed 9.1.4-0ubuntu11.10
|
|
11.04 natty | Not in release | |
10.04 LTS lucid | Not in release | |
8.04 LTS hardy | Not in release |
Patch details
Package | Patch details |
---|---|
php5 |
References
Related Ubuntu Security Notices (USN)
- USN-1461-1
- PostgreSQL vulnerabilities
- 5 June 2012
- USN-1481-1
- PHP vulnerabilities
- 19 June 2012