Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-8867

Опубликовано: 22 мая 2016
Источник: debian
EPSS Средний

Описание

The openssl_random_pseudo_bytes function in ext/openssl/openssl.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 incorrectly relies on the deprecated RAND_pseudo_bytes function, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php7.0fixed7.0.0-1package
php5fixed5.6.12+dfsg-1package
php5fixed5.6.12+dfsg-0+deb8u1jessiepackage
php5fixed5.4.44-0+deb7u1wheezypackage

Примечания

  • https://bugs.php.net/bug.php?id=70014

  • https://bugs.launchpad.net/ubuntu/+source/php5/+bug/1534203

  • https://git.php.net/?p=php-src.git;a=commit;h=16023f3e3b9c06cf677c3c980e8d574e4c162827

  • Fixed in 7.0.0, 5.6.12, 5.5.28, 5.5.44

  • https://www.openwall.com/lists/oss-security/2016/04/21/8

EPSS

Процентиль: 94%
0.13368
Средний

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 10 лет назад

The openssl_random_pseudo_bytes function in ext/openssl/openssl.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 incorrectly relies on the deprecated RAND_pseudo_bytes function, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.

CVSS3: 3.7
redhat
почти 10 лет назад

The openssl_random_pseudo_bytes function in ext/openssl/openssl.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 incorrectly relies on the deprecated RAND_pseudo_bytes function, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.

CVSS3: 7.5
nvd
почти 10 лет назад

The openssl_random_pseudo_bytes function in ext/openssl/openssl.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 incorrectly relies on the deprecated RAND_pseudo_bytes function, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.

CVSS3: 7.5
github
почти 4 года назад

The openssl_random_pseudo_bytes function in ext/openssl/openssl.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 incorrectly relies on the deprecated RAND_pseudo_bytes function, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.

fstec
почти 10 лет назад

Уязвимость интерпретатора PHP, позволяющая нарушителю взломать криптографический механизм защиты

EPSS

Процентиль: 94%
0.13368
Средний