PT-2016-7719 · Google · Android+1

Publicado

2016-11-11

·

Atualizado

2016-11-29

·

CVE-2016-9277

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Android versions 4.4 through 5.1 on Samsung Note devices
Description The issue is related to an integer overflow in SystemUI, which can be exploited by attackers to cause a denial of service, resulting in a UI restart. This can be achieved through vectors involving APIs and an activity that computes an out-of-bounds array index.
Recommendations For Android versions 4.4 through 5.1 on Samsung Note devices, consider applying configuration changes to restrict access to the affected SystemUI component until a patch is available. As a temporary workaround, disabling the affected activity that computes the out-of-bounds array index may help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Correção

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-9277

Produtos afetados

Android
Systemui