CVE Vulnerabilities

CVE-2016-3913

Published: Oct 10, 2016 | Modified: Apr 12, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

media/libmediaplayerservice/MediaPlayerService.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 does not validate a certain static_cast operation, which allows attackers to gain privileges via a crafted application, aka internal bug 30204103.

Affected Software

NameVendorStart VersionEnd Version
AndroidGoogle4.0 (including)4.0 (including)
AndroidGoogle4.0.1 (including)4.0.1 (including)
AndroidGoogle4.0.2 (including)4.0.2 (including)
AndroidGoogle4.0.3 (including)4.0.3 (including)
AndroidGoogle4.0.4 (including)4.0.4 (including)
AndroidGoogle4.1 (including)4.1 (including)
AndroidGoogle4.1.2 (including)4.1.2 (including)
AndroidGoogle4.2 (including)4.2 (including)
AndroidGoogle4.2.1 (including)4.2.1 (including)
AndroidGoogle4.2.2 (including)4.2.2 (including)
AndroidGoogle4.3 (including)4.3 (including)
AndroidGoogle4.3.1 (including)4.3.1 (including)
AndroidGoogle4.4 (including)4.4 (including)
AndroidGoogle4.4.1 (including)4.4.1 (including)
AndroidGoogle4.4.2 (including)4.4.2 (including)
AndroidGoogle4.4.3 (including)4.4.3 (including)
AndroidGoogle5.0 (including)5.0 (including)
AndroidGoogle5.0.1 (including)5.0.1 (including)
AndroidGoogle5.1 (including)5.1 (including)
AndroidGoogle5.1.0 (including)5.1.0 (including)
AndroidGoogle6.0 (including)6.0 (including)
AndroidGoogle6.0.1 (including)6.0.1 (including)
AndroidGoogle7.0 (including)7.0 (including)
AndroidUbuntuesm-apps/xenial*
AndroidUbuntutrusty*
AndroidUbuntuvivid/stable-phone-overlay*
AndroidUbuntuxenial*
AndroidUbuntuyakkety*
AndroidUbuntuzesty*

References