Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-8867

Опубликовано: 22 мая 2016
Источник: debian

Описание

The openssl_random_pseudo_bytes function in ext/openssl/openssl.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 incorrectly relies on the deprecated RAND_pseudo_bytes function, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php7.0fixed7.0.0-1package
php5fixed5.6.12+dfsg-1package
php5fixed5.6.12+dfsg-0+deb8u1jessiepackage
php5fixed5.4.44-0+deb7u1wheezypackage

Примечания

  • https://bugs.php.net/bug.php?id=70014

  • https://bugs.launchpad.net/ubuntu/+source/php5/+bug/1534203

  • https://git.php.net/?p=php-src.git;a=commit;h=16023f3e3b9c06cf677c3c980e8d574e4c162827

  • Fixed in 7.0.0, 5.6.12, 5.5.28, 5.5.44

  • https://www.openwall.com/lists/oss-security/2016/04/21/8

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 10 лет назад

The openssl_random_pseudo_bytes function in ext/openssl/openssl.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 incorrectly relies on the deprecated RAND_pseudo_bytes function, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.

CVSS3: 3.7
redhat
больше 10 лет назад

The openssl_random_pseudo_bytes function in ext/openssl/openssl.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 incorrectly relies on the deprecated RAND_pseudo_bytes function, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.

CVSS3: 7.5
nvd
около 10 лет назад

The openssl_random_pseudo_bytes function in ext/openssl/openssl.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 incorrectly relies on the deprecated RAND_pseudo_bytes function, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.

CVSS3: 7.5
github
около 4 лет назад

The openssl_random_pseudo_bytes function in ext/openssl/openssl.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 incorrectly relies on the deprecated RAND_pseudo_bytes function, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.

fstec
около 10 лет назад

Уязвимость интерпретатора PHP, позволяющая нарушителю взломать криптографический механизм защиты