CVE Vulnerabilities

CVE-2016-6700

Published: Nov 25, 2016 | Modified: Apr 12, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An elevation of privilege vulnerability in libzipfile in Android 4.x before 4.4.4, 5.0.x before 5.0.2, and 5.1.x before 5.1.1 could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Android ID: A-30916186.

Affected Software

NameVendorStart VersionEnd Version
AndroidGoogle4.0 (including)4.0 (including)
AndroidGoogle4.0.1 (including)4.0.1 (including)
AndroidGoogle4.0.2 (including)4.0.2 (including)
AndroidGoogle4.0.3 (including)4.0.3 (including)
AndroidGoogle4.0.4 (including)4.0.4 (including)
AndroidGoogle4.1 (including)4.1 (including)
AndroidGoogle4.1.2 (including)4.1.2 (including)
AndroidGoogle4.2 (including)4.2 (including)
AndroidGoogle4.2.1 (including)4.2.1 (including)
AndroidGoogle4.2.2 (including)4.2.2 (including)
AndroidGoogle4.3 (including)4.3 (including)
AndroidGoogle4.3.1 (including)4.3.1 (including)
AndroidGoogle4.4 (including)4.4 (including)
AndroidGoogle4.4.1 (including)4.4.1 (including)
AndroidGoogle4.4.2 (including)4.4.2 (including)
AndroidGoogle4.4.3 (including)4.4.3 (including)
AndroidGoogle5.0 (including)5.0 (including)
AndroidGoogle5.0.1 (including)5.0.1 (including)
AndroidGoogle5.1 (including)5.1 (including)
AndroidGoogle5.1.0 (including)5.1.0 (including)
AndroidUbuntuesm-apps/xenial*
AndroidUbuntutrusty*
AndroidUbuntuupstream*
AndroidUbuntuvivid/stable-phone-overlay*
AndroidUbuntuxenial*
AndroidUbuntuyakkety*
AndroidUbuntuzesty*

References