CVE-2008-2108 - Unsocial Groves


The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5 when running on 64-bit systems performs a multiplication that generates a portion of zero bits during conversion due to insufficient precision which produces 24 bits of entropy and simplifies brute force attacks against protection mechanisms that use the rand and mt_rand functions.