2.6

CVE-2007-2727

Exploit
The mcrypt_create_iv function in ext/mcrypt/mcrypt.c in PHP before 4.4.7, 5.2.1, and possibly 5.0.x and other PHP 5 versions, calls php_rand_r with an uninitialized seed variable and therefore always generates the same initialization vector (IV), which might allow context-dependent attackers to decrypt certain data more easily because of the guessable encryption keys.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Php ≫ Php Version >= 4.4.0 < 4.4.7
Php ≫ Php Version >= 5.0.0 < 5.2.2
Php ≫ Php Version 4.0.1
Php ≫ Php Version 4.0.1 Update patch1
Php ≫ Php Version 4.0.1 Update patch2
Php ≫ Php Version 4.0.2
Php ≫ Php Version 4.0.3
Php ≫ Php Version 4.0.3 Update patch1
Php ≫ Php Version 4.0.4
Php ≫ Php Version 4.0.5
Php ≫ Php Version 4.0.6
Php ≫ Php Version 4.0.7
Php ≫ Php Version 4.0.7 Update rc1
Php ≫ Php Version 4.0.7 Update rc2
Php ≫ Php Version 4.0.7 Update rc3
Php ≫ Php Version 4.1.0
Php ≫ Php Version 4.1.1
Php ≫ Php Version 4.1.2
Php ≫ Php Version 4.2.0
Php ≫ Php Version 4.2.1
Php ≫ Php Version 4.2.2
Php ≫ Php Version 4.2.3
Php ≫ Php Version 4.3.0
Php ≫ Php Version 4.3.1
Php ≫ Php Version 4.3.2
Php ≫ Php Version 4.3.3
Php ≫ Php Version 4.3.4
Php ≫ Php Version 4.3.5
Php ≫ Php Version 4.3.6
Php ≫ Php Version 4.3.7
Php ≫ Php Version 4.3.8
Php ≫ Php Version 4.3.9
Php ≫ Php Version 4.3.10
Php ≫ Php Version 4.3.11
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.86% 0.765
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 2.6 4.9 2.9
AV:N/AC:H/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/26895
Broken Link
http://www.mandriva.com/security/advisories?name=MDKSA-2007:187
Broken Link
http://www.novell.com/linux/security/advisories/2007_15_sr.html
Third Party Advisory
http://blog.php-security.org/archives/80-Watching-the-PHP-CVS.html
Vendor Advisory
http://bugs.php.net/bug.php?id=40999
Vendor Advisory
http://cvs.php.net/viewvc.cgi/php-src/ext/mcrypt/mcrypt.c?r1=1.91.2.3.2.9&r2=1.91.2.3.2.10
Vendor Advisory
http://osvdb.org/36087
Broken Link
http://www.fortheloot.com/public/mcrypt.patch
Patch
Third Party Advisory
Exploit
http://www.php.net/ChangeLog-5.php
Vendor Advisory
http://www.securityfocus.com/bid/23984
Third Party Advisory
VDB Entry