Upstream information
Description
The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.NVD CVSS v2 Base Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N)
Novell/SUSE information
Novell Bugzilla entries: 766797, 766798, 766799 SUSE Security Advisories:- SUSE-SU-2012:0840-1, published Thu, 5 Jul 2012 03:08:30 +0200 (CEST)
- openSUSE-SU-2012:0826-1, published Wed, 4 Jul 2012 09:08:42 +0200 (CEST)
- openSUSE-SU-2012:1251-1, published Wed, 26 Sep 2012 17:09:15 +0200 (CEST)
- openSUSE-SU-2012:1288-1, published Thu, 4 Oct 2012 18:08:51 +0200 (CEST)
- openSUSE-SU-2012:1299-1, published Sat, 6 Oct 2012 15:09:52 +0200 (CEST)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SLE 11 SP2 DEBUGINFO |
| Builds SAT Patch Nr: 6440 |
| SUSE Linux Enterprise Software Development Kit 11 SP2 |
| Builds SAT Patch Nr: 6440 |
| SUSE Linux Enterprise Server 11 SP2 SUSE Linux Enterprise Server 11 SP2 for VMware |
| Builds SAT Patch Nr: 6440 |
| SLE 11 SP1 DEBUGINFO |
| sles11-sp1-vmware.x86-64 sled11-sp1.x86-64 sles11-sp2.ppc sled11-sp2.x86-64 sles11-sp2.s390x sles11-sp1.x86-64 sles11-sp1.ia64 sles11-sp1.s390x sles11-sp1.ppc sled11-sp1.x86 sles11-sp2.x86 sles11-sp2.x86-64 sles11-sp1-vmware.x86 sles11-sp1.x86 sles11-sp2.ia64 sled11-sp2.x86 SAT Patch Nr: 6697 |
| SUSE Linux Enterprise Desktop 11 SP1 SUSE Linux Enterprise Desktop 11 SP2 |
| sles11-sp1-vmware.x86-64 sled11-sp1.x86-64 sles11-sp2.ppc sled11-sp2.x86-64 sles11-sp2.s390x sles11-sp1.x86-64 sles11-sp1.ia64 sles11-sp1.s390x sles11-sp1.ppc sled11-sp1.x86 sles11-sp2.x86 sles11-sp2.x86-64 sles11-sp1-vmware.x86 sles11-sp1.x86 sles11-sp2.ia64 sled11-sp2.x86 SAT Patch Nr: 6697 |
| SUSE Linux Enterprise Server 11 SP1 SUSE Linux Enterprise Server 11 SP1 for VMware SUSE Linux Enterprise Server 11 SP2 |
| sles11-sp1-vmware.x86-64 sled11-sp1.x86-64 sles11-sp2.ppc sled11-sp2.x86-64 sles11-sp2.s390x sles11-sp1.x86-64 sles11-sp1.ia64 sles11-sp1.s390x sles11-sp1.ppc sled11-sp1.x86 sles11-sp2.x86 sles11-sp2.x86-64 sles11-sp1-vmware.x86 sles11-sp1.x86 sles11-sp2.ia64 sled11-sp2.x86 SAT Patch Nr: 6697 |
