CVE-2008-2108 describes a critical vulnerability in PHP 4.x (before 4.4.8) and 5.x (before 5.2.5) on 64-bit systems, where the GENERATE_SEED macro produces insufficient entropy (only 24 bits) for the rand and mt_rand functions due to a precision issue during multiplication. This weakness significantly simplifies brute-force attacks against protection mechanisms relying on these functions. The vulnerability carries a CVSS score of 9.8 (CRITICAL), indicating a network-exploitable flaw with low attack complexity, requiring no user interaction or privileges, and leading to high impacts on confidentiality, integrity, and availability. Its FAUCET Risk Score is 94/100, and it is categorized under CWE-331 (Insufficient Entropy). While there is no evidence of active exploitation, nor are there known Metasploit or ExploitDB modules, the vulnerability has garnered significant community discussion with 10 mentions, suggesting awareness and potential interest. It is not listed in CISA's KEV catalog and is considered inactive on the Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, < 4.4.8CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
>= 5.0.0, < 5.2.5CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
8CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:8:*:*:*:*:*:*:* | ||
9CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:9:*:*:*:*:*:*:* | ||
6.06CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.