PT-2017-1261 · Google · Android

Publicado

2017-01-27

·

Atualizado

2017-02-07

·

CVE-2016-8411

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions that have qmi qos srvc.c
Description The issue is related to a buffer overflow vulnerability while processing QMI QOS TLVs. This vulnerability can be exploited by a remote attacker to cause a denial of service through a specially crafted directory name, specified in the uid parameter, associated with the WAR file name, which can be included in a POST request.
Recommendations For Android versions that have qmi qos srvc.c, consider restricting access to the QMI QOS TLVs component to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the uid parameter in POST requests that may be associated with the WAR file name. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-00375
CVE-2016-8411

Produtos afetados

Android