CVE Vulnerabilities

CVE-2008-4107

Published: Sep 18, 2008 | Modified: Oct 30, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The (1) rand and (2) mt_rand functions in PHP 5.2.6 do not produce cryptographically strong random numbers, which allows attackers to leverage exposures in products that rely on these functions for security-relevant functionality, as demonstrated by the password-reset functionality in Joomla! 1.5.x and WordPress before 2.6.2, a different vulnerability than CVE-2008-2107, CVE-2008-2108, and CVE-2008-4102.

Affected Software

Name Vendor Start Version End Version
Php Php 4.0 4.0
Php Php 4.0 4.0
Php Php 4.0 4.0
Php Php 4.0 4.0
Php Php 4.0.0 4.0.0
Php Php 4.0.1 4.0.1
Php Php 4.0.1 4.0.1
Php Php 4.0.1 4.0.1
Php Php 4.0.2 4.0.2
Php Php 4.0.3 4.0.3
Php Php 4.0.4 4.0.4
Php Php 4.0.5 4.0.5
Php Php 4.0.6 4.0.6
Php Php 4.0.7 4.0.7
Php Php 4.0.7 4.0.7
Php Php 4.0.7 4.0.7
Php Php 4.0.7 4.0.7
Php Php 4.1.0 4.1.0
Php Php 4.1.1 4.1.1
Php Php 4.1.2 4.1.2
Php Php 4.2 4.2
Php Php 4.2.0 4.2.0
Php Php 4.2.1 4.2.1
Php Php 4.2.2 4.2.2
Php Php 4.2.3 4.2.3
Php Php 4.3.0 4.3.0
Php Php 4.3.1 4.3.1
Php Php 4.3.2 4.3.2
Php Php 4.3.3 4.3.3
Php Php 4.3.4 4.3.4
Php Php 4.3.5 4.3.5
Php Php 4.3.6 4.3.6
Php Php 4.3.7 4.3.7
Php Php 4.3.8 4.3.8
Php Php 4.3.9 4.3.9
Php Php 4.3.10 4.3.10
Php Php 4.3.11 4.3.11
Php Php 4.4.0 4.4.0
Php Php 4.4.1 4.4.1
Php Php 4.4.2 4.4.2
Php Php 4.4.3 4.4.3
Php Php 4.4.4 4.4.4
Php Php 4.4.5 4.4.5
Php Php 4.4.6 4.4.6
Php Php 4.4.7 4.4.7
Php Php * 4.4.8

References