SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com






Category:   OS (UNIX)  >   FreeBSD Kernel Vendors:   FreeBSD
FreeBSD crypt(3) Hash Generation Error May Generate Incorrect Hashes
SecurityTracker Alert ID:  1026995
SecurityTracker URL:  http://securitytracker.com/id/1026995
CVE Reference:   CVE-2012-2143   (Links to External Site)
Updated:  May 30 2012
Original Entry Date:  Apr 30 2012
Impact:   Modification of authentication information, Modification of system information
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): 7.4, 8.1, 8.2, 8.3, 9.0
Description:   A vulnerability was reported in FreeBSD. The system may generate incorrect hashes.

When the crypt(3) system call is hashing data that contains a character with only the most significant bit set (0x80), that character and all subsequent characters are ignored.

Impact:   The system may generate incorrect hashes.
Solution:   The vendor has issued a fix.

The vendor's advisory is available at:

http://security.FreeBSD.org/advisories/FreeBSD-SA-12:02.crypt.asc

Vendor URL:  security.FreeBSD.org/advisories/FreeBSD-SA-12:02.crypt.asc (Links to External Site)
Cause:   Input validation error, State error
Underlying OS:  

Message History:   This archive entry has one or more follow-up message(s) listed below.
Jun 5 2012 (Check Point Issues Fix for Check Point IPSO) FreeBSD crypt(3) Hash Generation Error May Generate Incorrect Hashes
Check Point has issued a hotfix for Check Point IPSO.
Jun 25 2012 (Red Hat Issues Fix for PostgreSQL) FreeBSD crypt(3) Hash Generation Error May Generate Incorrect Hashes   (bugzilla@redhat.com)
Red Hat has issued a fix for PostgreSQL for Red Hat Enterprise Linux 5.
Jun 25 2012 (Red Hat Issues Fix for PostgreSQL) FreeBSD crypt(3) Hash Generation Error May Generate Incorrect Hashes   (bugzilla@redhat.com)
Red Hat has issued a fix for PostgreSQL for Red Hat Enterprise Linux 5 and 6.



 Source Message Contents



[Original Message Not Available for Viewing]


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

Copyright 2014, SecurityGlobal.net LLC