[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253390

 
 

909

 
 

197257

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2012-091 --- postgresql9

ID: oval:org.secpod.oval:def:1601354Date: (C)2020-11-27   (M)2024-03-20
Class: PATCHFamily: unix




The crypt_des function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.

Platform:
Amazon Linux AMI
Product:
postgresql9
Reference:
ALAS-2012-91
CVE-2012-2143
CVE    1
CVE-2012-2143
CPE    2
cpe:/o:amazon:linux
cpe:/a:postgresql:postgresql9

© SecPod Technologies