The openssl_random_pseudo_bytes function in ext/openssl/openssl.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 incorrectly relies on the deprecated RAND_pseudo_bytes function, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2016-05-22 01:59
Updated : 2025-04-12 10:46
NVD link : CVE-2015-8867
Mitre link : CVE-2015-8867
CVE.ORG link : CVE-2015-8867
JSON object : View
Products Affected
php
- php
canonical
- ubuntu_linux
CWE
CWE-310
Cryptographic Issues