Skip to main content

Serious Bug Identified in Newly Released PHP 5.3.7

posted onAugust 23, 2011
by l33tdawg

The PHP development team is considering recalling the recently released PHP 5.3.7 after a serious bug was identified in the crypt() function.

PHP 5.3.7 was released last week as an important security and stability update, developers urging users to upgrade as soon as possible at the time.

However, since the crypt() bug was identified they advise people against it, effectively reverting their previous recommendation. If the crypt() function is used to validate passwords using salted MD5 hashes the operation fails, practically making authentication impossible.

Source

Tags

Software-Programming Security

You May Also Like

Recent News

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th