CVE Vulnerabilities

CVE-2016-2413

Published: Apr 18, 2016 | Modified: Apr 21, 2016
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

media/libmedia/IOMX.cpp in mediaserver in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not initialize a handle pointer, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26403627.

Affected Software

Name Vendor Start Version End Version
Android Google 5.0 (including) 5.0 (including)
Android Google 5.0.1 (including) 5.0.1 (including)
Android Google 5.1 (including) 5.1 (including)
Android Google 5.1.0 (including) 5.1.0 (including)
Android Google 6.0 (including) 6.0 (including)
Android Google 6.0.1 (including) 6.0.1 (including)
Android Ubuntu esm-apps/xenial *
Android Ubuntu trusty *
Android Ubuntu upstream *
Android Ubuntu vivid/stable-phone-overlay *
Android Ubuntu wily *
Android Ubuntu xenial *
Android Ubuntu yakkety *
Android Ubuntu zesty *

References