Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:10878
HistoryJan 15, 2019 - 8:53 a.m.

Authentication Bypass

2019-01-1508:53:32
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

0.002 Low

EPSS

Percentile

59.3%

postgresql is vulnerable to authentication bypass attacks. The vulnerability exists as the crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.

References