Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2008-2108

31
FAUCET Score

CVE-2008-2108 describes a critical vulnerability in PHP 4.x (before 4.4.8) and 5.x (before 5.2.5) on 64-bit systems, where the GENERATE_SEED macro produces insufficient entropy (only 24 bits) for the rand and mt_rand functions due to a precision issue during multiplication. This weakness significantly simplifies brute-force attacks against protection mechanisms relying on these functions. The vulnerability carries a CVSS score of 9.8 (CRITICAL), indicating a network-exploitable flaw with low attack complexity, requiring no user interaction or privileges, and leading to high impacts on confidentiality, integrity, and availability. Its FAUCET Risk Score is 94/100, and it is categorized under CWE-331 (Insufficient Entropy). While there is no evidence of active exploitation, nor are there known Metasploit or ExploitDB modules, the vulnerability has garnered significant community discussion with 10 mentions, suggesting awareness and potential interest. It is not listed in CISA's KEV catalog and is considered inactive on the Hot List.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.0.0, < 4.4.8CPE matchmatch criteria
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
>= 5.0.0, < 5.2.5CPE matchmatch criteria
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
8CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:8:*:*:*:*:*:*:*
9CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:9:*:*:*:*:*:*:*
6.06CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
4.29%
Probability of exploitation in next 30 days
EPSS Percentile
90.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0429 is in the 83rd percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 2.1Fixed in: php-0:4.1.2-2.20
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: php-0:4.3.2-48.ent
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: php-0:4.3.9-3.22.12
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: php-0:5.1.6-20.el5_2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Application Stack for RHEL 4Fixed in: php-0:5.1.6-3.el4s1.10
View patch

Vendor Advisories (1)

redhatCVE-2008-2108Low

PHP weak 64 bit random seed

May 6, 2008

References

archives.neohapsis.com / archives/fulldisclosure/2008-05/0103.html
Broken LinkExploit
secunia.com / advisories/30757
Broken Link
secunia.com / advisories/30828
Broken Link
secunia.com / advisories/31119
Broken Link
secunia.com / advisories/31124
Broken Link
secunia.com / advisories/31200
Broken Link
secunia.com / advisories/32746
Broken Link
secunia.com / advisories/35003
Broken Link
security.gentoo.org / glsa/glsa-200811-05.xml
Third Party Advisory
securityreason.com / securityalert/3859
Mailing List
exchange.xforce.ibmcloud.com / vulnerabilities/42226
Third Party AdvisoryVDB Entry
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10844
Broken Link
redhat.com / archives/fedora-package-announce/2008-June/msg00773.html
Mailing List
redhat.com / archives/fedora-package-announce/2008-June/msg00779.html
Mailing List
debian.org / security/2009/dsa-1789
Mailing List
mandriva.com / security/advisories
Broken Link
mandriva.com / security/advisories
Broken Link
mandriva.com / security/advisories
Broken Link
mandriva.com / security/advisories
Broken Link
mandriva.com / security/advisories
Broken Link
mandriva.com / security/advisories
Broken Link
redhat.com / support/errata/RHSA-2008-0505.html
Broken Link
redhat.com / support/errata/RHSA-2008-0544.html
Broken Link
redhat.com / support/errata/RHSA-2008-0545.html
Broken Link
redhat.com / support/errata/RHSA-2008-0546.html
Broken Link
redhat.com / support/errata/RHSA-2008-0582.html
Broken Link
securityfocus.com / archive/1/491683/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
sektioneins.de / advisories/SE-2008-02.txt
Broken LinkExploit
ubuntu.com / usn/usn-628-1
Third Party Advisory