CVE Vulnerabilities

CVE-2010-1128

Published: Mar 26, 2010 | Modified: Dec 10, 2010
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent attackers to guess values that were intended to be unpredictable, as demonstrated by session cookies generated by using the uniqid function.

Affected Software

Name Vendor Start Version End Version
Php Php * 5.2.12 (including)
Php Php 5.2.0 (including) 5.2.0 (including)
Php Php 5.2.1 (including) 5.2.1 (including)
Php Php 5.2.2 (including) 5.2.2 (including)
Php Php 5.2.3 (including) 5.2.3 (including)
Php Php 5.2.4 (including) 5.2.4 (including)
Php Php 5.2.5 (including) 5.2.5 (including)
Php Php 5.2.6 (including) 5.2.6 (including)
Php Php 5.2.7 (including) 5.2.7 (including)
Php Php 5.2.8 (including) 5.2.8 (including)
Php Php 5.2.9 (including) 5.2.9 (including)
Php Php 5.2.10 (including) 5.2.10 (including)
Php Php 5.2.11 (including) 5.2.11 (including)

References