PHP users warned of bugged update

By Stuart Sumner

23 Aug 2011

Be the first to comment

warning

Users of the PHP web scripting language have been warned off updating to the latest patch because of a bug that affects some cryptographic functions.

A bug report published four days after the release of version 5.3.7 highlighted the problem.

Further reading

The report stated that the crypt function, which is used to hash a text string (in other words, map a large amount of information into something smaller), no longer worked properly in the new build.

"If crypt() is executed with MD5 salts, the return value consists of the salt only. DES and BLOWFISH [block ciphers used in encryption] salts work as expected," the report stated.

The salt consists of random bits added to the hash that improve security by making it impossible for an attacker to crack all the passwords at once.

The developers of the PHP language have promised that the bug will be fixed in the next version, due shortly.

"Due to unfortunate issues with 5.3.7 users should wait with upgrading until 5.3.8 will be released (expected in few days)."

Reader comments

Have your say on this article

All fields required. Your email address will not be displayed on the site.

By submitting a comment you agree to abide by our Terms & Conditions

  • Digg
  • Tweet

Newsletters

Sign up for our FREE newsletters

Technology Patent Wars

Large companies such as Microsoft, Facebook and Google have been hoovering up technology patents recently. Is this stifling innovation?

87 %

5 %

8 %