CVE-2008-2107
Advisory lineage Upstream: 0 Downstream: 6
Modified
Published: 07 May 2008, 21:00
Last modified:07 Aug 2024, 08:49
Vulnerability Summary
Overall Risk (default)
medium
41/100 CVSS Score
7.5 HIGH
v2.0 (nvd)
EPSS Score
3.09% LOW
3% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
2 found
Dark Web
Not detected
Timeline
07 May 2008, 21:00
Published
Vulnerability first disclosed
07 Aug 2024, 08:49
Last Modified
Vulnerability information updated
Description
The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 32-bit systems, performs a multiplication using values that can produce a zero seed in rare circumstances, which allows context-dependent attackers to predict subsequent values of the rand and mt_rand functions and possibly bypass protection mechanisms that rely on an unknown initial seed.
CVSS Metrics
- v2.0•HIGH•Score: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS Trends
Current EPSS score: 3.09%• Percentile: 87%
Techniques & Countermeasures
- CWE-189•Numeric Errors
Weaknesses in this category are related to improper calculation or conversion of numbers.
Affected Systems
- Unknown•PHP
≤ 4.4.7 | 5 | 5.0.0:beta1 | 5.0.0:beta2 | 5.0.0:beta3 | 5.0.0:rc1 | 5.0.0:rc2 | 5.0.0:rc3 | 5.0.1 | 5.0.2 | 5.0.3 | 5.0.4 | 5.0.5 | 5.1.0 | 5.1.1 | 5.1.2 | 5.1.3 | 5.1.4 | 5.1.5 | 5.1.6 | 5.2.0 | 5.2.1 | 5.2.2 | 5.2.3 | 5.2.4
References (32)
- https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00779.html
- http://secunia.com/advisories/32746
- http://archives.neohapsis.com/archives/fulldisclosure/2008-05/0103.html
- http://security.gentoo.org/glsa/glsa-200811-05.xml
- http://www.redhat.com/support/errata/RHSA-2008-0546.html
- https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00773.html
- http://secunia.com/advisories/30828
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:128
- http://securityreason.com/securityalert/3859
- http://www.redhat.com/support/errata/RHSA-2008-0582.html
- http://www.ubuntu.com/usn/usn-628-1
- http://www.redhat.com/support/errata/RHSA-2008-0545.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42226
- http://secunia.com/advisories/31124
- http://secunia.com/advisories/30967
- http://secunia.com/advisories/31119
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:129
- http://secunia.com/advisories/31200
- http://secunia.com/advisories/30757
- http://www.redhat.com/support/errata/RHSA-2008-0544.html
- http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00001.html
- http://secunia.com/advisories/35003
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:125
- http://www.redhat.com/support/errata/RHSA-2008-0505.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:130
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:126
- http://www.securityfocus.com/archive/1/491683/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42284
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:127
- http://www.sektioneins.de/advisories/SE-2008-02.txt
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10644
- http://www.debian.org/security/2009/dsa-1789