Red Hat Bugzilla – Bug 732795
CVE-2011-3189 php: 5.3.7 crypt() only returns the salt for MD5 hashes
Last modified: 2011-08-24 02:51:25 EDT
PHP 5.3.7 contains a flaw where if crypt() is executed with MD5 salts, the return value conists of the salt only. This issue only affects version 5.3.7, it does not affect any prior versions. PHP 5.3.8 is expected to be released soon which will fix this issue.
Statement: Not vulnerable. This issue did not affect the versions of php as shipped with Red Hat Enterprise Linux 4, 5, or 6.
PHP 5.3.8 has been released to correct this flaw. References: https://bugs.php.net/bug.php?id=55439 http://www.php.net/releases/5_3_8.php