Serious Bug Identified in Newly Released PHP 5.3.7
The PHP development team is considering recalling the recently released PHP 5.3.7 after a serious bug was identified in the crypt() function.
PHP 5.3.7 was released last week as an important security and stability update, developers urging users to upgrade as soon as possible at the time.
However, since the crypt() bug was identified they advise people against it, effectively reverting their previous recommendation. If the crypt() function is used to validate passwords using salted MD5 hashes the operation fails, practically making authentication impossible.