6.4
CVSSv2

CVE-2010-1128

Published: 26/03/2010 Updated: 10/12/2010
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

The Linear Congruential Generator (LCG) in PHP prior to 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent malicious users to guess values that were intended to be unpredictable, as demonstrated by session cookies generated by using the uniqid function.

Vulnerable Product Search on Vulmon Subscribe to Product

php php 5.2.9

php php 5.2.8

php php 5.2.0

php php 5.2.11

php php 5.2.10

php php 5.2.1

php php 5.2.3

php php 5.2.2

php php

php php 5.2.5

php php 5.2.4

php php 5.2.7

php php 5.2.6

Vendor Advisories

Auke van Slooten discovered that PHP incorrectly handled certain xmlrpc requests An attacker could exploit this issue to cause the PHP server to crash, resulting in a denial of service This issue only affected Ubuntu 606 LTS, 804 LTS, 904 and 910 (CVE-2010-0397) ...
Several remote vulnerabilities have been discovered in PHP 5, an hypertext preprocessor The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2010-1917 The fnmatch function can be abused to conduct denial of service attacks (by crashing the interpreter) by the means of a stack overflow CVE-2010-2225 ...

Exploits

source: wwwsecurityfocuscom/bid/38430/info PHP is prone to a security vulnerability that affects LCG (Linear Congruential) entropy Attackers can exploit this issue to steal sessions or other sensitive data Versions prior to PHP 5213 are affected githubcom/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/33 ...