In BlackBerry QNX Software Development Platform (SDP) 6.6.0 and 6.5.0 SP1 and earlier, a loss of integrity vulnerability in the default configuration of the QNX SDP could allow an attacker being able to reduce the entropy of the PRNG, making other blended attacks more practical by gaining control over environmental factors that influence seed generation.
References
Link | Resource |
---|---|
http://support.blackberry.com/kb/articleDetail?language=en_US&articleNumber=000046674 | Vendor Advisory |
http://support.blackberry.com/kb/articleDetail?language=en_US&articleNumber=000046674 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 03:35
Type | Values Removed | Values Added |
---|---|---|
References | () http://support.blackberry.com/kb/articleDetail?language=en_US&articleNumber=000046674 - Vendor Advisory |
Information
Published : 2017-11-14 21:29
Updated : 2024-11-21 03:35
NVD link : CVE-2017-9371
Mitre link : CVE-2017-9371
CVE.ORG link : CVE-2017-9371
JSON object : View
Products Affected
blackberry
- qnx_software_development_platform
CWE
CWE-332
Insufficient Entropy in PRNG