CVE detail
CVE-2008-2107 — CVE-2008-2107
Published 2008-05-07 · Modified 2026-06-16 · Vendor php · Product php · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0339
EPSS probability
exploitation probability, 30d
88.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 32-bit systems, performs a multiplication using values that can produce a zero seed in rare circumstances, which allows context-dependent attackers to predict subsequent values of the rand and mt_rand functions and possibly bypass protection mechanisms that rely on an unknown initial seed.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References