4.3
CVE-2012-2143
- EPSS 8.18%
- Published 05.07.2012 14:55:02
- Last modified 11.04.2025 00:51:21
- Source secalert@redhat.com
- Teams watchlist Login
- Open Login
The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.
Data is provided by the National Vulnerability Database (NVD)
Postgresql ≫ Postgresql Version >= 8.3 < 8.3.19
Postgresql ≫ Postgresql Version >= 8.4 < 8.4.12
Postgresql ≫ Postgresql Version >= 9.0 < 9.0.8
Postgresql ≫ Postgresql Version >= 9.1 < 9.1.4
Debian ≫ Debian Linux Version6.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 8.18% | 0.919 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|