The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x...
Vulnerability Description
The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 32-bit systems, performs a multiplication using values that can produce a zero seed in rare circumstances, which allows context-dependent attackers to predict subsequent values of the rand and mt_rand functions and possibly bypass protection mechanisms that rely on an unknown initial seed.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-2107
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00779.html
- http://secunia.com/advisories/32746
- http://archives.neohapsis.com/archives/fulldisclosure/2008-05/0103.html
- http://security.gentoo.org/glsa/glsa-200811-05.xml
- http://www.redhat.com/support/errata/RHSA-2008-0546.html
- https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00773.html
- http://secunia.com/advisories/30828
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:128
- http://securityreason.com/securityalert/3859
- http://www.redhat.com/support/errata/RHSA-2008-0582.html
- http://www.ubuntu.com/usn/usn-628-1
- http://www.redhat.com/support/errata/RHSA-2008-0545.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42226
- http://secunia.com/advisories/31124
- http://secunia.com/advisories/30967
- http://secunia.com/advisories/31119
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:129
- http://secunia.com/advisories/31200
- http://secunia.com/advisories/30757
- http://www.redhat.com/support/errata/RHSA-2008-0544.html
- http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00001.html
- http://secunia.com/advisories/35003
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:125
- http://www.redhat.com/support/errata/RHSA-2008-0505.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:130
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:126
- http://www.securityfocus.com/archive/1/491683/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42284
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:127
- http://www.sektioneins.de/advisories/SE-2008-02.txt
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10644
- http://www.debian.org/security/2009/dsa-1789
More from php
View All →Affected Vendor
Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.