SB2014042908 - Information disclosure in Google, Google Android
Published: April 29, 2014 Updated: August 10, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2013-7373)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Android before 4.4 does not properly arrange for seeding of the OpenSSL PRNG, which makes it easier for attackers to defeat cryptographic protection mechanisms by leveraging use of the PRNG within multiple applications.
Remediation
Install update from vendor's website.
References
- http://android-developers.blogspot.com.au/2013/08/some-securerandom-thoughts.html
- http://emboss.github.io/blog/2013/08/21/openssl-prng-is-not-really-fork-safe/
- http://marc.info/?l=openssl-dev&m=130289811108150&w=2
- http://marc.info/?l=openssl-dev&m=130298304903422&w=2
- http://www.reddit.com/r/Android/comments/1k6f03/due_to_a_serious_encryptionrng_flaw_in_android/cblvum5