MEDIUM
Drupal 6.x before 6.29 and 7.x before 7.24 uses the PHP mt_rand function to generate random numbers, which uses predictable seeds and allows remote attackers to predict security strings and bypass intended restrictions via a brute force attack
Published Dec 7, 2013
6.8
MEDIUMCVSS 2.0
EPSS 2.08%
Description
Drupal 6.x before 6.29 and 7.x before 7.24 uses the PHP mt_rand function to generate random numbers, which uses predictable seeds and allows remote attackers to predict security strings and bypass intended restrictions via a brute force attack.
Affected products
No data.
Configuration 1
OR
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.1
- 7.2
- 7.3
- 7.4
- 7.5
- 7.6
- 7.7
- 7.8
- 7.9
- 7.10
- 7.11
- 7.12
- 7.13
- 7.14
- 7.15
- 7.16
- 7.17
- 7.18
- 7.19
- 7.20
- 7.21
- 7.22
- 7.23
- 7.x-dev
Configuration 2
OR
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.1
- 6.2
- 6.3
- 6.4
- 6.5
- 6.6
- 6.7
- 6.8
- 6.9
- 6.10
- 6.11
- 6.12
- 6.13
- 6.14
- 6.15
- 6.16
- 6.17
- 6.18
- 6.19
- 6.20
- 6.21
- 6.22
- 6.23
- 6.24
- 6.25
- 6.26
- 6.27
- 6.28
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- http://secunia.com/advisories/56148 third-party-advisoryx_refsource_SECUNIA
- http://www.debian.org/security/2013/dsa-2804 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2013/dsa-2828 vendor-advisoryx_refsource_DEBIAN
- http://www.openwall.com/lists/oss-security/2013/11/22/4 mailing-listx_refsource_MLIST
- https://drupal.org/SA-CORE-2013-003 x_refsource_CONFIRMPatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://secunia.com/advisories/56148 | third-party-advisoryx_refsource_SECUNIA | |
| http://www.debian.org/security/2013/dsa-2804 | vendor-advisoryx_refsource_DEBIAN | |
| http://www.debian.org/security/2013/dsa-2828 | vendor-advisoryx_refsource_DEBIAN | |
| http://www.openwall.com/lists/oss-security/2013/11/22/4 | mailing-listx_refsource_MLIST | |
| https://drupal.org/SA-CORE-2013-003 | x_refsource_CONFIRMPatchVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 7, 2013
Updated Aug 6, 2024
Reserved Nov 4, 2013
Link CVE-2013-6386
CISA Vulnrichment
Updated n/a