5
CVSSv2

CVE-2015-8867

Published: 22/05/2016 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The openssl_random_pseudo_bytes function in ext/openssl/openssl.c in PHP prior to 5.4.44, 5.5.x prior to 5.5.28, and 5.6.x prior to 5.6.12 incorrectly relies on the deprecated RAND_pseudo_bytes function, which makes it easier for remote malicious users to defeat cryptographic protection mechanisms via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

php php

canonical ubuntu linux 12.04

canonical ubuntu linux 15.10

canonical ubuntu linux 14.04

Vendor Advisories

Synopsis Moderate: rh-php56 security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for rh-php56, rh-php56-php, and rh-php56-php-pear is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Mo ...
The openssl_random_pseudo_bytes function in ext/openssl/opensslc in PHP before 5444, 55x before 5528, and 56x before 5612 incorrectly relies on the deprecated RAND_pseudo_bytes function, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors ...