libril/RilSapSocket.cpp in Telephony in Android 6.x before 2016-10-01 and 7.0 before 2016-10-01 relies on variable-length arrays, which allows attackers to gain privileges via a crafted application, aka internal bug 30202619.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Android | 6.0.1 | 6.0.1 | |
Android | 6.0 | 6.0 | |
Android | 7.0 | 7.0 |