CVE-2008-2108
07.05.2008, 21:20
The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 64-bit systems, performs a multiplication that generates a portion of zero bits during conversion due to insufficient precision, which produces 24 bits of entropy and simplifies brute force attacks against protection mechanisms that use the rand and mt_rand functions.Enginsight
| Vendor | Product | Version |
|---|---|---|
| php | php | 4.0.0 ≤ 𝑥 < 4.4.8 |
| php | php | 5.0.0 ≤ 𝑥 < 5.2.5 |
| canonical | ubuntu_linux | 6.06 |
| canonical | ubuntu_linux | 7.04 |
| canonical | ubuntu_linux | 7.10 |
| canonical | ubuntu_linux | 8.04 |
| debian | debian_linux | 4.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration
References