CVE-2008-3072: High severity simple machines forum vulnerability
Published Jul 8, 2008
·Updated
Simple Machines Forum (SMF) 1.1.x before 1.1.5 and 1.0.x before 1.0.13, when running in PHP before 4.2.0, does not properly seed the random number generator, which has unknown impact and attack vectors.
Affected Software
2 affected components
Simple Machines Simple Machines Forum<=1.0.12
Simple Machines Simple Machines Forum<=1.1.4
Event History
Jul 8, 2008
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-3072?
CVE-2008-3072 is classified as having an unknown severity due to its undefined impact and attack vectors.
2
How do I fix CVE-2008-3072?
To fix CVE-2008-3072, upgrade to Simple Machines Forum version 1.1.5 or 1.0.13 or later.
3
What versions of Simple Machines Forum are affected by CVE-2008-3072?
CVE-2008-3072 affects Simple Machines Forum versions 1.0.12 and earlier and 1.1.4 and earlier.
4
What impact does CVE-2008-3072 have on security?
CVE-2008-3072 may lead to potential vulnerabilities due to improper seeding of the random number generator.
5
Is there a known exploit for CVE-2008-3072?
There are currently no known exploits for CVE-2008-3072, but the implications are concerning due to the random number generator issue.