Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2013-7373

Description

Android before 4.4 does not properly arrange for seeding of the OpenSSL PRNG, which makes it easier for attackers to defeat cryptographic protection mechanisms by leveraging use of the PRNG within multiple applications.

POC

Reference

- http://emboss.github.io/blog/2013/08/21/openssl-prng-is-not-really-fork-safe/

- http://www.reddit.com/r/Android/comments/1k6f03/due_to_a_serious_encryptionrng_flaw_in_android/cblvum5

Github

- https://github.com/ARPSyndicate/cvemon

- https://github.com/chnzzh/OpenSSL-CVE-lib