cve/2015/CVE-2015-8867.md
2024-05-26 14:27:05 +02:00

804 B

CVE-2015-8867

Description

The openssl_random_pseudo_bytes function in ext/openssl/openssl.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 incorrectly relies on the deprecated RAND_pseudo_bytes function, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.

POC

Reference

No PoCs from references.

Github