PHP contains a flaw that is triggered when an error occurs during the handling of empty salt strings. This may allow a remote attacker to bypass authentication.
Currently, there are no known workarounds or upgrades to correct this issue. However, Ubuntu has released a patch to address this vulnerability. Check the vendor changelog in the references section.