Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The PRNG implementation in the DNS resolver in Bionic in Android before 4.1.1 incorrectly uses time and PID information during the generation of random numbers for query ID values and UDP source ports, which makes it easier for remote attackers to spoof DNS responses by guessing these numbers, a related issue to CVE-2015-0800.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Android Bionic 安全漏洞
Vulnerability Description
Google Chrome是美国谷歌(Google)公司开发的一款Web浏览器。Android是美国谷歌(Google)公司和开放手持设备联盟(简称OHA)共同开发的一套以Linux为基础的开源操作系统。 Android 4.1.0及之前版本的Bionic中的DNS解析程序的PRNG实现过程中存在安全漏洞,该漏洞源于程序生成用于查询ID值和UDP源端口的随机数时,没有正确使用时间和PID信息。远程攻击者可通过猜测随机数利用该漏洞伪造DNS响应。
CVSS Information
N/A
Vulnerability Type
N/A