CVE-2008-2107

Publication date 7 May 2008

Last updated 24 July 2024


Ubuntu priority

The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 32-bit systems, performs a multiplication using values that can produce a zero seed in rare circumstances, which allows context-dependent attackers to predict subsequent values of the rand and mt_rand functions and possibly bypass protection mechanisms that rely on an unknown initial seed.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
php5 8.04 LTS hardy
Fixed 5.2.4-2ubuntu5.3
7.10 gutsy
Fixed 5.2.3-1ubuntu6.4
7.04 feisty
Fixed 5.2.1-0ubuntu1.6
6.06 LTS dapper
Fixed 5.1.2-1ubuntu3.12

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
php5

References

Related Ubuntu Security Notices (USN)

Other references