PT-2010-2844 · Php+1 · Php+1

Grzegorz Stachowiak

·

Publicado

2010-03-26

·

Atualizado

2010-12-10

·

CVE-2010-1128

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.2.13
Description The Linear Congruential Generator (LCG) in PHP does not provide the expected entropy, making it easier for attackers to guess values that were intended to be unpredictable, such as session cookies generated by the uniqid function.
Recommendations For versions prior to 5.2.13, update to version 5.2.13 or later to resolve the issue.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-1128
DSA-2195-1
RHSA-2010:0919
RHSA-2010_0919

Produtos afetados

Php
Red Hat