CVE-2007-2728: Medium severity PHP PHP vulnerability
Published May 16, 2007
·Updated
The soap extension in PHP calls phprandr with an uninitialized seed variable, which has unknown impact and attack vectors, a related issue to the mcryptcreateiv issue covered by CVE-2007-2727.
Affected Software
4 affected components
PHP PHP
Ubuntu=6.06
Ubuntu=6.10
Ubuntu=7.04
Event History
May 16, 2007
CVE Published
via NVD·10:30 PM
May 17, 2007
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2728?
CVE-2007-2728 has an unknown severity due to its uninitialized seed variable in the soap extension.
2
How do I fix CVE-2007-2728?
To fix CVE-2007-2728, it is recommended to update PHP to a version that does not contain this vulnerability.
3
What software is affected by CVE-2007-2728?
CVE-2007-2728 affects PHP and specific versions of Ubuntu Linux including 6.06, 6.10, and 7.04.
4
What impact does CVE-2007-2728 have?
The impact of CVE-2007-2728 is currently unknown but is related to random number generation issues.
5
Is CVE-2007-2728 related to any other vulnerabilities?
Yes, CVE-2007-2728 is related to CVE-2007-2727, which also concerns random number generation in PHP.