We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2007-2728



Assignermitre
Reserved2007-05-16
Published2007-05-16
Updated2024-08-29

Description

The soap extension in PHP calls php_rand_r with an uninitialized seed variable, which has unknown impact and attack vectors, a related issue to the mcrypt_create_iv issue covered by CVE-2007-2727. Note: The PHP team argue that this is not a valid security issue.

References

http://secunia.com/advisories/25306 (25306) third-party-advisory

http://blog.php-security.org/archives/80-Watching-the-PHP-CVS.html

http://www.vupen.com/english/advisories/2007/1839 (ADV-2007-1839) vdb-entry

http://www.ubuntu.com/usn/usn-485-1 (USN-485-1) vendor-advisory

http://www.mandriva.com/security/advisories?name=MDKSA-2007:187 (MDKSA-2007:187) vendor-advisory

http://secunia.com/advisories/26895 (26895) third-party-advisory

http://secunia.com/advisories/26102 (26102) third-party-advisory

http://osvdb.org/36086 (36086) vdb-entry

http://www.novell.com/linux/security/advisories/2007_15_sr.html (SUSE-SR:2007:015) vendor-advisory

cve.org CVE-2007-2728

nvd.nist.gov CVE-2007-2728

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2007-2728
Support options

Helpdesk Telegram

Subscribe to our newsletter to learn more about our work.