CVE-2007-2728

The soap extension in PHP calls php_rand_r with an uninitialized seed variable, which has unknown impact and attack vectors, a related issue to the mcrypt_create_iv issue covered by CVE-2007-2727.
Configurations

Configuration 1 (hide)

cpe:2.3:a:php:php:-:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:6.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:7.04:*:*:*:*:*:*:*

History

31 Mar 2021, 16:05

Type Values Removed Values Added
References (MANDRIVA) http://www.mandriva.com/security/advisories?name=MDKSA-2007:187 - (MANDRIVA) http://www.mandriva.com/security/advisories?name=MDKSA-2007:187 - Third Party Advisory
References (SECUNIA) http://secunia.com/advisories/26895 - Vendor Advisory (SECUNIA) http://secunia.com/advisories/26895 - Third Party Advisory
References (UBUNTU) http://www.ubuntu.com/usn/usn-485-1 - (UBUNTU) http://www.ubuntu.com/usn/usn-485-1 - Third Party Advisory
References (SECUNIA) http://secunia.com/advisories/26102 - Vendor Advisory (SECUNIA) http://secunia.com/advisories/26102 - Third Party Advisory
References (OSVDB) http://osvdb.org/36086 - (OSVDB) http://osvdb.org/36086 - Broken Link
References (SUSE) http://www.novell.com/linux/security/advisories/2007_15_sr.html - (SUSE) http://www.novell.com/linux/security/advisories/2007_15_sr.html - Broken Link
References (SECUNIA) http://secunia.com/advisories/25306 - Vendor Advisory (SECUNIA) http://secunia.com/advisories/25306 - Third Party Advisory
References (VUPEN) http://www.vupen.com/english/advisories/2007/1839 - Vendor Advisory (VUPEN) http://www.vupen.com/english/advisories/2007/1839 - Third Party Advisory
References (MISC) http://blog.php-security.org/archives/80-Watching-the-PHP-CVS.html - (MISC) http://blog.php-security.org/archives/80-Watching-the-PHP-CVS.html - Broken Link
CPE cpe:2.3:a:php:php:*:*:*:*:*:*:*:* cpe:2.3:o:canonical:ubuntu_linux:7.04:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*
cpe:2.3:a:php:php:-:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:6.10:*:*:*:*:*:*:*
CVSS v2 : 4.3
v3 : unknown
v2 : 5.0
v3 : unknown
CWE CWE-264 NVD-CWE-noinfo

Information

Published : 2007-05-16 22:30

Updated : 2023-12-10 10:40


NVD link : CVE-2007-2728

Mitre link : CVE-2007-2728

CVE.ORG link : CVE-2007-2728


JSON object : View

Products Affected

canonical

  • ubuntu_linux

php

  • php