CVE Vulnerabilities

CVE-2011-3918

Published: Oct 07, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Zygote process in Android 4.0.3 and earlier accepts fork requests from processes with arbitrary UIDs, which allows remote attackers to cause a denial of service (reboot loop) via a crafted application.

Affected Software

NameVendorStart VersionEnd Version
AndroidGoogle*4.0.3 (including)
AndroidGoogle1.0 (including)1.0 (including)
AndroidGoogle1.1 (including)1.1 (including)
AndroidGoogle1.5 (including)1.5 (including)
AndroidGoogle1.6 (including)1.6 (including)
AndroidGoogle2.0 (including)2.0 (including)
AndroidGoogle2.0.1 (including)2.0.1 (including)
AndroidGoogle2.1 (including)2.1 (including)
AndroidGoogle2.2 (including)2.2 (including)
AndroidGoogle2.2-rev1 (including)2.2-rev1 (including)
AndroidGoogle2.2.1 (including)2.2.1 (including)
AndroidGoogle2.2.2 (including)2.2.2 (including)
AndroidGoogle2.2.3 (including)2.2.3 (including)
AndroidGoogle2.3 (including)2.3 (including)
AndroidGoogle2.3-rev1 (including)2.3-rev1 (including)
AndroidGoogle2.3.1 (including)2.3.1 (including)
AndroidGoogle2.3.2 (including)2.3.2 (including)
AndroidGoogle2.3.3 (including)2.3.3 (including)
AndroidGoogle2.3.4 (including)2.3.4 (including)
AndroidGoogle2.3.5 (including)2.3.5 (including)
AndroidGoogle2.3.6 (including)2.3.6 (including)
AndroidGoogle2.3.7 (including)2.3.7 (including)
AndroidGoogle3.0 (including)3.0 (including)
AndroidGoogle3.1 (including)3.1 (including)
AndroidGoogle3.2 (including)3.2 (including)
AndroidGoogle3.2.1 (including)3.2.1 (including)
AndroidGoogle3.2.2 (including)3.2.2 (including)
AndroidGoogle3.2.4 (including)3.2.4 (including)
AndroidGoogle3.2.6 (including)3.2.6 (including)
AndroidGoogle4.0 (including)4.0 (including)
AndroidGoogle4.0.1 (including)4.0.1 (including)
AndroidGoogle4.0.2 (including)4.0.2 (including)

References