First published: Tue Apr 29 2014(Updated: )
Android before 4.4 does not properly arrange for seeding of the OpenSSL PRNG, which makes it easier for attackers to defeat cryptographic protection mechanisms by leveraging use of the PRNG within multiple applications.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Android | <=4.3.1 | |
Android | =1.0 | |
Android | =1.1 | |
Android | =1.5 | |
Android | =1.6 | |
Android | =2.0 | |
Android | =2.0.1 | |
Android | =2.1 | |
Android | =2.2 | |
Android | =2.2-rev1 | |
Android | =2.2.1 | |
Android | =2.2.2 | |
Android | =2.2.3 | |
Android | =2.3 | |
Android | =2.3-rev1 | |
Android | =2.3.1 | |
Android | =2.3.2 | |
Android | =2.3.3 | |
Android | =2.3.4 | |
Android | =2.3.5 | |
Android | =2.3.6 | |
Android | =2.3.7 | |
Android | =3.0 | |
Android | =3.1 | |
Android | =3.2 | |
Android | =3.2.1 | |
Android | =3.2.2 | |
Android | =3.2.4 | |
Android | =3.2.6 | |
Android | =4.0 | |
Android | =4.0.1 | |
Android | =4.0.2 | |
Android | =4.0.3 | |
Android | =4.0.4 | |
Android | =4.1 | |
Android | =4.1.2 | |
Android | =4.2 | |
Android | =4.2.1 | |
Android | =4.2.2 | |
Android | =4.3 | |
<=4.3.1 | ||
=1.0 | ||
=1.1 | ||
=1.5 | ||
=1.6 | ||
=2.0 | ||
=2.0.1 | ||
=2.1 | ||
=2.2 | ||
=2.2-rev1 | ||
=2.2.1 | ||
=2.2.2 | ||
=2.2.3 | ||
=2.3 | ||
=2.3-rev1 | ||
=2.3.1 | ||
=2.3.2 | ||
=2.3.3 | ||
=2.3.4 | ||
=2.3.5 | ||
=2.3.6 | ||
=2.3.7 | ||
=3.0 | ||
=3.1 | ||
=3.2 | ||
=3.2.1 | ||
=3.2.2 | ||
=3.2.4 | ||
=3.2.6 | ||
=4.0 | ||
=4.0.1 | ||
=4.0.2 | ||
=4.0.3 | ||
=4.0.4 | ||
=4.1 | ||
=4.1.2 | ||
=4.2 | ||
=4.2.1 | ||
=4.2.2 | ||
=4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-7373 is considered a high severity vulnerability due to its impact on cryptographic security in Android.
To fix CVE-2013-7373, upgrade your Android version to 4.4 or later to ensure proper seeding of the OpenSSL PRNG.
CVE-2013-7373 affects all Android versions prior to 4.4, including 1.0 up to 4.3.1.
CVE-2013-7373 allows attackers to potentially defeat cryptographic protections by exploiting weaknesses in the PRNG.
CVE-2013-7373 can affect multiple applications on Android devices that rely on the OpenSSL PRNG.