The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent attackers to guess values that were intended to be unpredictable, as demonstrated by session cookies generated by using the uniqid function.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade php-xmlUpgrade php-imapUpgrade php-odbcUpgrade php-xmlrpcUpgrade php-mbstringUpgrade php-cliUpgrade php-domxmlUpgrade php-ncursesUpgrade php-mysqlUpgrade php-snmpUpgrade php-commonUpgrade php-gdUpgrade phpUpgrade php-pgsqlUpgrade php-pearUpgrade php-pdoUpgrade php-develUpgrade php-bcmathUpgrade php-ldapUpgrade php-dbaUpgrade php-soap | Dec 1, 2016 | Mar 26, 2010 |
| Gentoo Linux | — | Upgrade dev-lang/php. | Oct 30, 2017 | Mar 26, 2010 |
| Oracle_linux | — | Upgrade php-soapUpgrade php-dbaUpgrade php-mbstringUpgrade php-mysqlUpgrade php-ncursesUpgrade php-xmlrpcUpgrade php-pdoUpgrade phpUpgrade php-gdUpgrade php-cliUpgrade php-pgsqlUpgrade php-ldapUpgrade php-develUpgrade php-snmpUpgrade php-xmlUpgrade php-odbcUpgrade php-commonUpgrade php-bcmathUpgrade php-imap | Oct 16, 2024 | Mar 26, 2010 |
| Php | — | Upgrade to PHP version 5.2.13 | Oct 1, 2012 | Mar 26, 2010 |
| Ubuntu | — | Upgrade libapache2-mod-php5Upgrade php5-cgiUpgrade php5-cli | Nov 8, 2024 | Mar 26, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub