CVE-2012-2143

medium
Published 2012-07-05 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
4.3

Description

The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

OS impact

debian Debian Affected 1 release
VersionStatusFixed in
6.0 Affected โ€”
freebsd FreeBSD Affected 59 releases
VersionStatusFixed in
8.3 Affected โ€”
8.2 Affected โ€”
8.1 Affected โ€”
8.0 Affected โ€”
7.4 Affected โ€”
7.3 Affected โ€”
7.2 Affected โ€”
7.1 Affected โ€”
7.0 Affected โ€”
6.4 Affected โ€”
6.3 Affected โ€”
6.2 Affected โ€”
6.1 Affected โ€”
6.0 Affected โ€”
5.5 Affected โ€”
5.4 Affected โ€”
5.3 Affected โ€”
5.2.1 Affected โ€”
5.2 Affected โ€”
5.1 Affected โ€”
5.0 Affected โ€”
4.9 Affected โ€”
4.8 Affected โ€”
4.7 Affected โ€”
4.6.2 Affected โ€”
4.6 Affected โ€”
4.5 Affected โ€”
4.4 Affected โ€”
4.3 Affected โ€”
4.2 Affected โ€”
4.11 Affected โ€”
4.10 Affected โ€”
4.1.1 Affected โ€”
4.1 Affected โ€”
4.0 Affected โ€”
3.5 Affected โ€”
3.4 Affected โ€”
3.3 Affected โ€”
3.2 Affected โ€”
3.1 Affected โ€”
3.0 Affected โ€”
2.2.8 Affected โ€”
2.2.7 Affected โ€”
2.2.6 Affected โ€”
2.2.5 Affected โ€”
2.2.2 Affected โ€”
2.2.1 Affected โ€”
2.2 Affected โ€”
2.1.7 Affected โ€”
2.1.6 Affected โ€”
2.1.5 Affected โ€”
2.1 Affected โ€”
2.0.5 Affected โ€”
2.0 Affected โ€”
1.1.5.1 Affected โ€”
1.1.5 Affected โ€”
1.1 Affected โ€”
1.0 Affected โ€”
โ€” Affected โ€”

Application impact

VendorProductVersionsFixed
postgresql postgresqlpostgresql{"startIncluding":"8.3","endExcluding":"8.3.19"}8.3.19
php phpphp{"endExcluding":"5.3.14"}5.3.14
postgresql postgresqlpostgresql{"startIncluding":"8.4","endExcluding":"8.4.12"}8.4.12
postgresql postgresqlpostgresql{"startIncluding":"9.0","endExcluding":"9.0.8"}9.0.8
postgresql postgresqlpostgresql{"startIncluding":"9.1","endExcluding":"9.1.4"}9.1.4

References

CWEs

CWE-310

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.