CVE-2015-8867: High severity php vulnerability
The opensslrandompseudobytes function in ext/openssl/openssl.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 incorrectly relies on the deprecated RANDpseudobytes function, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.
Other sources
Fixed bug (opensslrandompseudobytes() is not cryptographically secure). (CVE-2015-8867)
— PHP
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8867?
CVE-2015-8867 is considered a medium severity vulnerability due to its potential impact on cryptographic protection mechanisms.
How do I fix CVE-2015-8867?
To fix CVE-2015-8867, upgrade PHP to version 5.4.44, 5.5.28, 5.6.12 or later.
Which PHP versions are affected by CVE-2015-8867?
CVE-2015-8867 affects PHP versions prior to 5.4.44, 5.5.28, and 5.6.12.
What are the implications of CVE-2015-8867 for my application?
CVE-2015-8867 could allow remote attackers to undermine cryptographic protections in your application.
Is CVE-2015-8867 specific to certain operating systems?
CVE-2015-8867 impacts PHP installations across various operating systems, including specific versions of Ubuntu.