WordPress Core < 2.6.2 - Cryptographic Weakness

2008-09-08 00:00
Stefan Esser

Strategic Overview

Status
Patched in 2.6.2
Affected CoreWordPress 2.6
Affected Version<= 2.6.1
CVSS6.5Medium
CVECVE-2008-4107
View all WordPress 2.6 vulnerabilities

Vulnerability Overview

The (1) rand and (2) mt_rand functions in PHP 5.2.6 do not produce cryptographically strong random numbers, which allows attackers to leverage exposures in products that rely on these functions for security-relevant functionality, as demonstrated by the password-reset functionality in Joomla! 1.5.x and WordPress before 2.6.2, a different vulnerability than CVE-2008-2107, CVE-2008-2108, and CVE-2008-4102.

Technical Analysis

REMEDIATION: Update to version 2.6.2, or a newer patched version --- IDENTIFIER: CWE-327 (Use of a Broken or Risky Cryptographic Algorithm) The product uses a broken or risky cryptographic algorithm or protocol.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C