[php-maint] Crypt in PHP 5.3.7

Lior Kaplan kaplanlior at gmail.com
Tue Aug 23 08:05:55 UTC 2011


On Mon, Aug 22, 2011 at 12:24 AM, Ondřej Surý <ondrej at debian.org> wrote:

> Hi Lior,
>
> thanks for heads up, fortunately I have some good news. Ccing Debian
> Security Team as well.
>
> Debian's PHP is fine, because it does use system crypt() implementation
> for available ciphers and uses PHP implementation only for algorithms
> not implemented in the system library (e.g. blowfish).
>
> Stable with php5-cli 5.3.7-1:
> # php -r 'printf("MD5: %s\n", crypt("password", "\$1\$U7AjYB.O$"));'
> MD5: $1$U7AjYB.O$L1N7ux7twaMIMw0En8UUR1
>

I guess we should tell something to our users as they might be worried about
http://www.php.net/archive/2011.php#id2011-08-22-1 and seeing 5.3.7 already
in Debian unstable.

Kaplan
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.alioth.debian.org/pipermail/pkg-php-maint/attachments/20110823/69cc5cf7/attachment.html>


More information about the pkg-php-maint mailing list