Lucene search

K
ubuntucveUbuntu.comUB:CVE-2015-0800
HistoryApr 01, 2015 - 12:00 a.m.

CVE-2015-0800

2015-04-0100:00:00
ubuntu.com
ubuntu.com
17

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.003

Percentile

70.6%

The PRNG implementation in the DNS resolver in Mozilla Firefox (aka Fennec)
before 37.0 on Android does not properly generate random numbers for query
ID values and UDP source ports, which makes it easier for remote attackers
to spoof DNS responses by guessing these numbers, a related issue to
CVE-2012-2808.

Notes

Author Note
chrisccoulson Affects Android only

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.003

Percentile

70.6%