Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-59wc-4gch-hhw5

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent attackers to guess values that were intended to be unpredictable, as demonstrated by session cookies generated by using the uniqid function.

The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent attackers to guess values that were intended to be unpredictable, as demonstrated by session cookies generated by using the uniqid function.

EPSS

Процентиль: 92%
0.08464
Низкий

Связанные уязвимости

ubuntu
больше 15 лет назад

The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent attackers to guess values that were intended to be unpredictable, as demonstrated by session cookies generated by using the uniqid function.

redhat
больше 15 лет назад

The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent attackers to guess values that were intended to be unpredictable, as demonstrated by session cookies generated by using the uniqid function.

nvd
больше 15 лет назад

The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent attackers to guess values that were intended to be unpredictable, as demonstrated by session cookies generated by using the uniqid function.

debian
больше 15 лет назад

The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not ...

oracle-oval
почти 15 лет назад

ELSA-2010-0919: php security update (MODERATE)

EPSS

Процентиль: 92%
0.08464
Низкий