php: openssl_random_pseudo_bytes() is not cryptographically secure
Published May 22, 2016
7.5
HIGHCVSS 3.0
EPSS 4.35%
Description
The openssl_random_pseudo_bytes function in ext/openssl/openssl.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 incorrectly relies on the deprecated RAND_pseudo_bytes function, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.
Affected products
No data.
Configuration 1
Configuration 2
- 12.04
- 14.04
- 15.10
No data.
Red Hat Software Collections for Red Hat Enterprise Linux 6
rh-php56-0:2.3-1.el6
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 6
rh-php56-php-0:5.6.25-1.el6
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 6
rh-php56-php-pear-1:1.9.5-4.el6
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS
rh-php56-0:2.3-1.el6
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS
rh-php56-php-0:5.6.25-1.el6
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS
rh-php56-php-pear-1:1.9.5-4.el6
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-php56-0:2.3-1.el7
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-php56-php-0:5.6.25-1.el7
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-php56-php-pear-1:1.9.5-4.el7
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS
rh-php56-0:2.3-1.el7
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS
rh-php56-php-0:5.6.25-1.el7
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS
rh-php56-php-pear-1:1.9.5-4.el7
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS
rh-php56-0:2.3-1.el7
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS
rh-php56-php-0:5.6.25-1.el7
Fixed · RHSA-2016:2750
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS
rh-php56-php-pear-1:1.9.5-4.el7
Fixed · RHSA-2016:2750
Red Hat Enterprise Linux 5
php
Will not fix
Red Hat Enterprise Linux 5
php53
Will not fix
Red Hat Enterprise Linux 6
php
Will not fix
Red Hat Enterprise Linux 7
php
Will not fix
Red Hat Software Collections
php54-php
Will not fix
Red Hat Software Collections
php55-php
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-php56-0:2.3-1.el6 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-php56-php-0:5.6.25-1.el6 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-php56-php-pear-1:1.9.5-4.el6 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | rh-php56-0:2.3-1.el6 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | rh-php56-php-0:5.6.25-1.el6 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | rh-php56-php-pear-1:1.9.5-4.el6 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-php56-0:2.3-1.el7 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-php56-php-0:5.6.25-1.el7 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-php56-php-pear-1:1.9.5-4.el7 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS | rh-php56-0:2.3-1.el7 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS | rh-php56-php-0:5.6.25-1.el7 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS | rh-php56-php-pear-1:1.9.5-4.el7 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS | rh-php56-0:2.3-1.el7 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS | rh-php56-php-0:5.6.25-1.el7 | Fixed | RHSA-2016:2750 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS | rh-php56-php-pear-1:1.9.5-4.el7 | Fixed | RHSA-2016:2750 |
| Red Hat Enterprise Linux 5 | php | Will not fix | n/a |
| Red Hat Enterprise Linux 5 | php53 | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | php | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | php | Will not fix | n/a |
| Red Hat Software Collections | php54-php | Will not fix | n/a |
| Red Hat Software Collections | php55-php | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (16)
- http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=16023f3e3b9c06cf677c3c980e8d574e4c162827 x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00031.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00033.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00056.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2750.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.openwall.com/lists/oss-security/2016/04/24/1 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.php.net/ChangeLog-5.php x_refsource_CONFIRMVendor Advisory
- http://www.php.net/ChangeLog-7.php x_refsource_CONFIRMVendor Advisory
- http://www.ubuntu.com/usn/USN-2952-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/USN-2952-2 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2015-8867 Vendor Advisory
- https://bugs.launchpad.net/ubuntu/+source/php5/+bug/1534203 x_refsource_CONFIRMThird Party Advisory
- https://bugs.php.net/bug.php?id=70014 x_refsource_CONFIRMVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1330420 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2015-8867
- https://www.cve.org/CVERecord?id=CVE-2015-8867
Change history (0)
No recorded changes yet.