Lucene search

K
cveMitreCVE-2010-1128
HistoryMar 26, 2010 - 8:30 p.m.

CVE-2010-1128

2010-03-2620:30:00
CWE-310
mitre
web.nvd.nist.gov
86
cve-2010-1128
php
linear congruential generator
entropy
uniqid function

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

AI Score

9.2

Confidence

High

EPSS

0.009

Percentile

83.1%

The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent attackers to guess values that were intended to be unpredictable, as demonstrated by session cookies generated by using the uniqid function.

Affected configurations

Nvd
Node
phpphpRange5.2.12
OR
phpphpMatch5.2.0
OR
phpphpMatch5.2.1
OR
phpphpMatch5.2.2
OR
phpphpMatch5.2.3
OR
phpphpMatch5.2.4
OR
phpphpMatch5.2.5
OR
phpphpMatch5.2.6
OR
phpphpMatch5.2.7
OR
phpphpMatch5.2.8
OR
phpphpMatch5.2.9
OR
phpphpMatch5.2.10
OR
phpphpMatch5.2.11
VendorProductVersionCPE
phpphp5.2.4cpe:/a:php:php:5.2.4:::
phpphp5.2.9cpe:/a:php:php:5.2.9:::
phpphp5.2.5cpe:/a:php:php:5.2.5:::
phpphp5.2.7cpe:/a:php:php:5.2.7:::
phpphpcpe:/a:php:php::::
phpphp5.2.8cpe:/a:php:php:5.2.8:::
phpphp5.2.6cpe:/a:php:php:5.2.6:::
phpphp5.2.2cpe:/a:php:php:5.2.2:::
phpphp5.2.3cpe:/a:php:php:5.2.3:::
phpphp5.2.1cpe:/a:php:php:5.2.1:::
Rows per page:
1-10 of 131

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

AI Score

9.2

Confidence

High

EPSS

0.009

Percentile

83.1%