PT-2016-1583 · Google · Android

Publicado

2016-03-12

·

Atualizado

2016-11-28

·

CVE-2016-0825

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android 6.0.1 before 2016-03-01
Description The issue allows attackers to obtain sensitive TrustZone secure-storage information by leveraging kernel access. This can be achieved by obtaining Signature or SignatureOrSystem access. The vulnerability is related to errors in security settings of the Android operating system. Exploitation of the vulnerability may allow a remote attacker to gain access to protected TrustZone information by utilizing the kernel.
Recommendations For Android 6.0.1 before 2016-03-01, update the system to a version released after 2016-03-01 to resolve the issue. As a temporary workaround, consider restricting kernel access to minimize the risk of exploitation.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-00884
CVE-2016-0825

Produtos afetados

Android