The PRNG implementation in the DNS resolver in Bionic in Android before 4.1.1 incorrectly uses time and PID information during the generation of random numbers for query ID values and UDP source ports, which makes it easier for remote attackers to spoof DNS responses by guessing these numbers, a related issue to CVE-2015-0800.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade linux-seamonkeyUpgrade firefoxUpgrade seamonkeyUpgrade thunderbirdUpgrade libxulUpgrade linux-firefoxUpgrade linux-thunderbirdUpgrade firefox-esr | Dec 10, 2025 | Mar 31, 2015 |
| Mfsa2015 41 | — | — | Apr 2, 2015 | Apr 1, 2015 |
| Suse | — | Upgrade MozillaFirefox-develUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefoxUpgrade MozillaFirefox-translations-other | Aug 9, 2024 | Jul 9, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub