Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-8867

Опубликовано: 22 мая 2016
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5
CVSS3: 7.5

Описание

The openssl_random_pseudo_bytes function in ext/openssl/openssl.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 incorrectly relies on the deprecated RAND_pseudo_bytes function, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

released

5.5.9+dfsg-1ubuntu4.16
precise

released

5.3.10-1ubuntu3.22
trusty

released

5.5.9+dfsg-1ubuntu4.16
trusty/esm

released

5.5.9+dfsg-1ubuntu4.16
upstream

released

5.6.12+dfsg-1
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

wily

released

5.6.11+dfsg-1ubuntu3.2
xenial

DNE

Показывать по

РелизСтатусПримечание
devel

not-affected

esm-infra-legacy/trusty

DNE

esm-infra-legacy/xenial

not-affected

7.0.4-7ubuntu2
esm-infra/xenial

not-affected

7.0.4-7ubuntu2
precise

DNE

trusty

DNE

trusty/esm

DNE

upstream

released

7.0.0-1
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

Показывать по

EPSS

Процентиль: 90%
0.04353
Низкий

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 3.7
redhat
больше 10 лет назад

The openssl_random_pseudo_bytes function in ext/openssl/openssl.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 incorrectly relies on the deprecated RAND_pseudo_bytes function, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.

CVSS3: 7.5
nvd
около 10 лет назад

The openssl_random_pseudo_bytes function in ext/openssl/openssl.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 incorrectly relies on the deprecated RAND_pseudo_bytes function, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.

CVSS3: 7.5
debian
около 10 лет назад

The openssl_random_pseudo_bytes function in ext/openssl/openssl.c in P ...

CVSS3: 7.5
github
около 4 лет назад

The openssl_random_pseudo_bytes function in ext/openssl/openssl.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 incorrectly relies on the deprecated RAND_pseudo_bytes function, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.

fstec
около 10 лет назад

Уязвимость интерпретатора PHP, позволяющая нарушителю взломать криптографический механизм защиты

EPSS

Процентиль: 90%
0.04353
Низкий

5 Medium

CVSS2

7.5 High

CVSS3