CVE-2012-2143

UnknownEPSS 5.73%

Last modified

CVE-2012-2143 is a vulnerability of currently unknown severity. The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.. EPSS estimates a 5.73% chance of exploitation in the next 30 days.

Description

The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.

Metrics

EPSS Probability
5.73%

92.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
PostgresqlPostgresql>= 8.3, < 8.3.19
PostgresqlPostgresql>= 8.4, < 8.4.12
PostgresqlPostgresql>= 9.0, < 9.0.8
PostgresqlPostgresql>= 9.1, < 9.1.4
FreebsdFreebsd<= 9.0
FreebsdFreebsd1.0
FreebsdFreebsd1.1
FreebsdFreebsd1.1.5
FreebsdFreebsd1.1.5.1
FreebsdFreebsd2.0
FreebsdFreebsd2.0.5
FreebsdFreebsd2.1
FreebsdFreebsd2.1.5
FreebsdFreebsd2.1.6
FreebsdFreebsd2.1.7
FreebsdFreebsd2.2
FreebsdFreebsd2.2.1
FreebsdFreebsd2.2.2
FreebsdFreebsd2.2.5
FreebsdFreebsd2.2.6
FreebsdFreebsd2.2.7
FreebsdFreebsd2.2.8
FreebsdFreebsd3.0
FreebsdFreebsd3.1
FreebsdFreebsd3.2
FreebsdFreebsd3.3
FreebsdFreebsd3.4
FreebsdFreebsd3.5
FreebsdFreebsd4.0
FreebsdFreebsd4.1
FreebsdFreebsd4.1.1
FreebsdFreebsd4.2
FreebsdFreebsd4.3
FreebsdFreebsd4.4
FreebsdFreebsd4.5
FreebsdFreebsd4.6
FreebsdFreebsd4.6.2
FreebsdFreebsd4.7
FreebsdFreebsd4.8
FreebsdFreebsd4.9
FreebsdFreebsd4.10
FreebsdFreebsd4.11
FreebsdFreebsd5.0
FreebsdFreebsd5.1
FreebsdFreebsd5.2
FreebsdFreebsd5.2.1
FreebsdFreebsd5.3
FreebsdFreebsd5.4
FreebsdFreebsd5.5
FreebsdFreebsd6.0

Showing 50 of 66 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2012-2143?
The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.
How severe is CVE-2012-2143?
Severity scoring for CVE-2012-2143 is pending analysis. The EPSS model estimates a 5.73% probability of exploitation in the next 30 days.
How do I fix CVE-2012-2143?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2012-2143?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST