<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title>PHPDeveloper.org</title>
    <link>http://www.phpdeveloper.org</link>
    <description>Up-to-the Minute PHP News, views and community</description>
    <language>en-us</language>
    <pubDate>Sat, 25 May 2013 23:21:27 -0500</pubDate>
    <ttl>30</ttl>
    <item>
      <title><![CDATA[Secunia.com: PHP SOAP Extension HTTP Authentication Weak Nonce]]></title>
      <guid>http://www.phpdeveloper.org/news/7852</guid>
      <link>http://www.phpdeveloper.org/news/7852</link>
      <description><![CDATA[<p>
Secunia has <a href="http://secunia.com/advisories/25306/">a new advisory</a> posted concerning an issue discovered with PHP's SOAP extension's HTTP authentication mechanism:
</p>
<blockquote>
The weakness is caused due to the use of an uninitialized variable within the function "make_http_soap_request()" of the SOAP extension when calling "php_rand_r()" to generate the nonce for the digest authentication, which may result in a weak and predictable nonce.
</blockquote>
<p>
The <a href="http://secunia.com/advisories/25306/">issue</a> is marked as "less critical" but should still be taken into consideration. The issue has been corrected in the <a href="http://cvs.php.net/viewvc.cgi/php-src/ext/soap/php_http.c?r1=1.77.2.11.2.8&r2=1.77.2.11.2.9">latest CVS commit</a>.
</p>]]></description>
      <pubDate>Wed, 16 May 2007 09:31:00 -0500</pubDate>
    </item>
  </channel>
</rss>
