CVE-2012-2143: Debian Linux

Medium severity, CVSS 4.3. EPSS: 5.7% chance of exploitation in the next 30 days.

The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.

Affected products

  • Debian Debian Linux: version 6.0 only
  • Freebsd Freebsd: up to and including 9.0; version 1.0 only; version 1.1 only; version 1.1.5 only; version 1.1.5.1 only; version 2.0 only; …
  • PHP PHP: before 5.3.14 (fixed in 5.3.14); from 5.4.0, before 5.4.4 (fixed in 5.4.4)
  • PostgreSQL PostgreSQL: from 8.3, before 8.3.19 (fixed in 8.3.19); from 8.4, before 8.4.12 (fixed in 8.4.12); from 9.0, before 9.0.8 (fixed in 9.0.8); from 9.1, before 9.1.4 (fixed in 9.1.4)

Published 2012-07-05. Last modified 2026-06-16.