CVE-2007-2727
Summary
| CVE | CVE-2007-2727 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-05-16 22:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The mcrypt_create_iv function in ext/mcrypt/mcrypt.c in PHP before 4.4.7, 5.2.1, and possibly 5.0.x and other PHP 5 versions, calls php_rand_r with an uninitialized seed variable and therefore always generates the same initialization vector (IV), which might allow context-dependent attackers to decrypt certain data more easily because of the guessable encryption keys. |
Risk And Classification
Primary CVSS: v2.0 2.6 from [email protected]
AV:N/AC:H/Au:N/C:P/I:N/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:H/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| cvs.php.net/viewvc.cgi/php-src/ext/mcrypt/mcrypt.c | af854a3a-2127-422b-91ae-364da2661108 | cvs.php.net | Vendor Advisory |
| PHP Bugs: #40999: mcrypt_create_iv() not using random seed. | af854a3a-2127-422b-91ae-364da2661108 | bugs.php.net | Vendor Advisory |
| PHP MCrypt_Create_IV Insecure Encryption Weakness | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| PHP: PHP 5 ChangeLog | af854a3a-2127-422b-91ae-364da2661108 | www.php.net | Vendor Advisory |
| Mandriva update for php - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| Watching the PHP CVS - PHP Security Blog | af854a3a-2127-422b-91ae-364da2661108 | blog.php-security.org | Vendor Advisory |
| Advisories | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | Broken Link |
| Security Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | Third Party Advisory |
| osvdb.org/36087 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | Broken Link |
| www.fortheloot.com/public/mcrypt.patch | af854a3a-2127-422b-91ae-364da2661108 | www.fortheloot.com | Exploit, Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2008-06-26 | Mark J Cox | Not vulnerable. This issue did not affect the versions of php as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5, or Red Hat Application Stack 1, or 2, as the packages shipped are not compiled with the mcrypt extension affected by this issue. |
There are currently no legacy QID mappings associated with this CVE.