CVE-2008-2108
The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 64-bit systems, performs a multiplication that generates a portion of zero bits during conversion due to insufficient precision, which produces 24 bits of entropy and…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.29%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 64-bit systems, performs a multiplication that generates a portion of zero bits during conversion due to insufficient precision, which produces 24 bits of entropy and simplifies brute force attacks against protection mechanisms that use the rand and mt_rand functions.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.29% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-331
- Affected
- php/php · fedoraproject/fedora · canonical/ubuntu linux · debian/debian linux
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/fulldisclosure/2008-05/0103.htmlBroken Link, Exploit
- http://secunia.com/advisories/30757Broken Link
- http://secunia.com/advisories/30828Broken Link
- http://secunia.com/advisories/31119Broken Link
- http://secunia.com/advisories/31124Broken Link
- http://secunia.com/advisories/31200Broken Link
- http://secunia.com/advisories/32746Broken Link
- http://secunia.com/advisories/35003Broken Link
- http://security.gentoo.org/glsa/glsa-200811-05.xmlThird Party Advisory
- http://securityreason.com/securityalert/3859Mailing List
- http://www.debian.org/security/2009/dsa-1789Mailing List
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:125Broken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:126Broken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:127Broken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:128Broken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:129Broken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:130Broken Link
- http://www.redhat.com/support/errata/RHSA-2008-0505.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2008-0544.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2008-0545.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2008-0546.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2008-0582.htmlBroken Link
- http://www.securityfocus.com/archive/1/491683/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.sektioneins.de/advisories/SE-2008-02.txtBroken Link, Exploit
- http://www.ubuntu.com/usn/usn-628-1Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42226Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10844Broken Link
- https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00773.htmlMailing List
- https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00779.htmlMailing List
- http://archives.neohapsis.com/archives/fulldisclosure/2008-05/0103.htmlBroken Link, Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.