Back

MEDIUM

crypt_blowfish: 8-bit character mishandling allows different password pairs to produce the same hash

Published Aug 25, 2011

Description

crypt_blowfish before 1.1, as used in PHP before 5.3.7 on certain platforms, PostgreSQL before 8.4.9, and other products, does not properly handle 8-bit characters, which makes it easier for context-dependent attackers to determine a cleartext password by leveraging knowledge of a password hash.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (27)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 25, 2011
Updated Aug 6, 2024
Reserved Jun 15, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Jun 20, 2011