PHP 5.3.7 contains a flaw where if crypt() is executed with MD5 salts, the return value conists of the salt only. This issue only affects version 5.3.7, it does not affect any prior versions. PHP 5.3.8 is expected to be released soon which will fix this issue.
Statement: Not vulnerable. This issue did not affect the versions of php as shipped with Red Hat Enterprise Linux 4, 5, or 6.
PHP 5.3.8 has been released to correct this flaw. References: https://bugs.php.net/bug.php?id=55439 http://www.php.net/releases/5_3_8.php