In random_get_bytes of random.c, there is a possible degradation of randomness due to an insecure default value. This could lead to local information disclosure via an insecure wireless connection with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-117508900.
References
Link Resource
http://www.securityfocus.com/bid/106946 Third Party Advisory VDB Entry
https://source.android.com/security/bulletin/2019-02-01 Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: google_android

Published: 2019-02-04T00:00:00

Updated: 2019-03-01T10:57:01

Reserved: 2018-12-10T00:00:00


Link: CVE-2019-1997

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-02-28T17:29:00.943

Modified: 2019-03-01T16:21:37.117


Link: CVE-2019-1997

JSON object: View

cve-icon Redhat Information

No data.

CWE