Oval Definition:oval:com.ubuntu.xenial:def:201619020000000
Revision Date:2016-06-01Version:1
Title:CVE-2016-1902 on Ubuntu 16.04 LTS (xenial) - medium.
Description:The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate random numbers when used with PHP 5.x without the paragonie/random_compat library and the openssl_random_pseudo_bytes function fails, which makes it easier for attackers to defeat cryptographic protection mechanisms via unspecified vectors.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2016-1902
Platform(s):Ubuntu 16.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 16.04 LTS (xenial) is installed.
  • AND symfony package in xenial, is related to the CVE in some way and has been fixed (note: '2.7.9+dfsg-1').
  • BACK