CVE-2012-2143: Debian Linux
Medium severity, CVSS 4.3. EPSS: 5.7% chance of exploitation in the next 30 days.
The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.
Affected products
- Debian Debian Linux: version 6.0 only
- Freebsd Freebsd: up to and including 9.0; version 1.0 only; version 1.1 only; version 1.1.5 only; version 1.1.5.1 only; version 2.0 only; …
- PHP PHP: before 5.3.14 (fixed in 5.3.14); from 5.4.0, before 5.4.4 (fixed in 5.4.4)
- PostgreSQL PostgreSQL: from 8.3, before 8.3.19 (fixed in 8.3.19); from 8.4, before 8.4.12 (fixed in 8.4.12); from 9.0, before 9.0.8 (fixed in 9.0.8); from 9.1, before 9.1.4 (fixed in 9.1.4)
Published 2012-07-05. Last modified 2026-06-16.