PT-2023-9407 · Php+10 · Php+10

Tim Düsterhus

+1

·

Published

2023-01-05

·

Updated

2025-08-11

·

CVE-2023-0567

CVSS v3.1

8.1

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions PHP versions 8.0.0 through 8.0.27 PHP versions 8.1.0 through 8.1.15 PHP versions 8.2.0 through 8.2.2
Description The issue is related to the password verification function in PHP, which may accept some invalid Blowfish hashes as valid. If such an invalid hash ends up in the password database, it may lead to an application allowing any password for this entry as valid. This is due to insufficient computation of the password hash. The password verify() function is specifically affected.
Recommendations For PHP versions 8.0.0 through 8.0.27, update to version 8.0.28 or later. For PHP versions 8.1.0 through 8.1.15, update to version 8.1.16 or later. For PHP versions 8.2.0 through 8.2.2, update to version 8.2.3 or later. As a temporary workaround, consider restricting access to the password verify() function until a patch is available. Avoid using invalid Blowfish hashes in the password database to minimize the risk of exploitation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

ALSA-2023:5926
ALSA-2023:5927
ALSA-2024:0387
ALSA-2024:10952
ALT-PU-2023-1246
ALT-PU-2023-1251
ALT-PU-2023-1256
ALT-PU-2023-1275
ALT-PU-2023-1284
ALT-PU-2023-1319
ALT-PU-2023-8445
AZL-13740
BDU:2024-07326
BIT-LIBPHP-2023-0567
BIT-PHP-2023-0567
BIT-PHP-MIN-2023-0567
CESA-2023_5927
CESA-2024_10952
CVE-2023-0567
DLA-3345-1
DSA-5363-1
GHSA-7FJ2-8X79-RJF4
INFSA-2023_5926
INFSA-2024_10952
MGASA-2023-0065
OESA-2023-1619
OESA-2023-1620
OESA-2023-1621
OESA-2023-1622
OPENSUSE-SU-2024:12711-1
RHSA-2023:5926
RHSA-2023:5927
RHSA-2023_5926
RHSA-2023_5927
RHSA-2024:0387
RHSA-2024:10952
RHSA-2024_0387
RHSA-2024_10952
RLSA-2023:5926
RLSA-2023:5927
RLSA-2024:0387
RLSA-2024:10952
SUSE-SU-2023:0476-1
SUSE-SU-2023:0513-1
SUSE-SU-2023:0514-1
SUSE-SU-2023:0515-1
SUSE-SU-2023_0513-1
SUSE-SU-2023_0514-1
SUSE-SU-2023_0515-1
USN-5902-1
USN-6053-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Php
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu