AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2012-2317

MEDIUM · CVSS 4.3 EPSS 2.46%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2012-08-07 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2012-2317
Severity
MEDIUM
CVSS
4.3
EPSS
2.46%
Linux Ubuntu Debian

Original NVD Description

The Debian php_crypt_revamped.patch patch for PHP 5.3.x, as used in the php5 package before 5.3.3-7+squeeze4 in Debian GNU/Linux squeeze, the php5 package before 5.3.2-1ubuntu4.17 in Ubuntu 10.04 LTS, and the php5 package before 5.3.5-1ubuntu7.10 in Ubuntu 11.04, does not properly handle an empty salt string, which might allow remote attackers to bypass authentication by leveraging an application that relies on the PHP crypt function to choose a salt for password hashing.