CVE Vulnerabilities

CVE-2016-0849

Published: Apr 18, 2016 | Modified: Apr 12, 2025
CVSS 3.x
8.4
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Multiple integer overflows in minzip/SysUtil.c in the Recovery Procedure in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allow attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26960931.

Affected Software

NameVendorStart VersionEnd Version
AndroidGoogle5.0 (including)5.0 (including)
AndroidGoogle5.0.1 (including)5.0.1 (including)
AndroidGoogle5.1 (including)5.1 (including)
AndroidGoogle5.1.0 (including)5.1.0 (including)
AndroidGoogle6.0 (including)6.0 (including)
AndroidGoogle6.0.1 (including)6.0.1 (including)
AndroidUbuntuesm-apps/xenial*
AndroidUbuntutrusty*
AndroidUbuntuupstream*
AndroidUbuntuvivid/stable-phone-overlay*
AndroidUbuntuwily*
AndroidUbuntuxenial*
AndroidUbuntuyakkety*
AndroidUbuntuzesty*

References