PT-2019-16026 · Google · Android

Publicado

2019-02-28

·

Atualizado

2019-03-01

·

CVE-2019-1997

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android versions 7.0 through 9
Description The issue is related to a possible degradation of randomness in the random get bytes function of random.c, which could lead to local information disclosure via an insecure wireless connection. No additional execution privileges are needed, and user interaction is not required for exploitation.
Recommendations For Android versions 7.0 through 9, update to a version that includes a fix for the insecure default value in the random get bytes function.

Correção

Use of Insufficiently Random Values

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-1997

Produtos afetados

Android