Back to search
CVE-2007-2727
Published: May 16, 2007
Modified: Aug 7, 2024
PUBLISHED
Description
The mcrypt_create_iv function in ext/mcrypt/mcrypt.c in PHP before 4.4.7, 5.2.1, and possibly 5.0.x and other PHP 5 versions, calls php_rand_r with an uninitialized seed variable and therefore always generates the same initialization vector (IV), which might allow context-dependent attackers to decrypt certain data more easily because of the guessable encryption keys.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
23984
vdb-entry
x_refsource_BID
http://www.fortheloot.com/public/mcrypt.patch
x_refsource_MISC
http://www.php.net/ChangeLog-5.php
x_refsource_CONFIRM
http://bugs.php.net/bug.php?id=40999
x_refsource_CONFIRM
MDKSA-2007:187
vendor-advisory
x_refsource_MANDRIVA
26895
third-party-advisory
x_refsource_SECUNIA
SUSE-SR:2007:015
vendor-advisory
x_refsource_SUSE
36087
vdb-entry
x_refsource_OSVDB
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now