CVE-2013-7373: Infoleak
Published Apr 29, 2014
·Updated
Android before 4.4 does not properly arrange for seeding of the OpenSSL PRNG, which makes it easier for attackers to defeat cryptographic protection mechanisms by leveraging use of the PRNG within multiple applications.
Affected Software
40 affected components
Google Android<=4.3.1
Google Android=1.0
Google Android=1.1
Google Android=1.5
Google Android=1.6
Google Android=2.0
Google Android=2.0.1
Google Android=2.1
Google Android=2.2
Google Android=2.2-rev1
Google Android=2.2.1
Google Android=2.2.2
Google Android=2.2.3
Google Android=2.3
Google Android=2.3-rev1
Google Android=2.3.1
Google Android=2.3.2
Google Android=2.3.3
Google Android=2.3.4
Google Android=2.3.5
Google Android=2.3.6
Google Android=2.3.7
Google Android=3.0
Google Android=3.1
Google Android=3.2
Google Android=3.2.1
Google Android=3.2.2
Google Android=3.2.4
Google Android=3.2.6
Google Android=4.0
Google Android=4.0.1
Google Android=4.0.2
Google Android=4.0.3
Google Android=4.0.4
Google Android=4.1
Google Android=4.1.2
Google Android=4.2
Google Android=4.2.1
Google Android=4.2.2
Google Android=4.3
Event History
Apr 29, 2014
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-7373?
CVE-2013-7373 is considered a high severity vulnerability due to its impact on cryptographic security in Android.
2
How do I fix CVE-2013-7373?
To fix CVE-2013-7373, upgrade your Android version to 4.4 or later to ensure proper seeding of the OpenSSL PRNG.
3
Which versions of Android are affected by CVE-2013-7373?
CVE-2013-7373 affects all Android versions prior to 4.4, including 1.0 up to 4.3.1.
4
What consequences can arise from CVE-2013-7373?
CVE-2013-7373 allows attackers to potentially defeat cryptographic protections by exploiting weaknesses in the PRNG.
5
Is CVE-2013-7373 related to any specific applications?
CVE-2013-7373 can affect multiple applications on Android devices that rely on the OpenSSL PRNG.