First published: Tue Apr 29 2014(Updated: )
Android before 4.4 does not properly arrange for seeding of the OpenSSL PRNG, which makes it easier for attackers to defeat cryptographic protection mechanisms by leveraging use of the PRNG within multiple applications.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | <=4.3.1 | |
Google Android | =1.0 | |
Google Android | =1.1 | |
Google Android | =1.5 | |
Google Android | =1.6 | |
Google Android | =2.0 | |
Google Android | =2.0.1 | |
Google Android | =2.1 | |
Google Android | =2.2 | |
Google Android | =2.2-rev1 | |
Google Android | =2.2.1 | |
Google Android | =2.2.2 | |
Google Android | =2.2.3 | |
Google Android | =2.3 | |
Google Android | =2.3-rev1 | |
Google Android | =2.3.1 | |
Google Android | =2.3.2 | |
Google Android | =2.3.3 | |
Google Android | =2.3.4 | |
Google Android | =2.3.5 | |
Google Android | =2.3.6 | |
Google Android | =2.3.7 | |
Google Android | =3.0 | |
Google Android | =3.1 | |
Google Android | =3.2 | |
Google Android | =3.2.1 | |
Google Android | =3.2.2 | |
Google Android | =3.2.4 | |
Google Android | =3.2.6 | |
Google Android | =4.0 | |
Google Android | =4.0.1 | |
Google Android | =4.0.2 | |
Google Android | =4.0.3 | |
Google Android | =4.0.4 | |
Google Android | =4.1 | |
Google Android | =4.1.2 | |
Google Android | =4.2 | |
Google Android | =4.2.1 | |
Google Android | =4.2.2 | |
Google Android | =4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.