4 ms·
Android 4.1.1 is the vulnerable version. Google says only 4.1.1 is vulnerable. There are a handful of services on Android that use openssl and, I suppose, could
by larrysilverman 12y ago
Android 4.1.1 is the vulnerable version. Google says only 4.1.1 is vulnerable. There are a handful of services on Android that use openssl and, I suppose, could present open ports for there to be an attack vector. See http://www.pcmag.com/article2/0,2817,2456507,00.asp http://www.pcmag.com/article2/0,2817,2456507,00.asp
- mikeash 12y agoYou can also MITM outgoing SSL connections and use heartbleed on them. The vulnerability is accessible before the certificate checks are completed, so the standard MITM prevention measures don't help you there.