PT-2014-8342 · Google · Android

Jann Horn

·

Published

2014-12-15

·

Updated

2014-12-16

·

CVE-2014-7911

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android versions prior to 5.0.0
Description The issue concerns the java.io.ObjectInputStream implementation in Android, where deserialization does not properly verify that the resulting object meets serialization requirements. This allows attackers to execute arbitrary code by crafting a finalize method for a serialized object in an ArrayMap Parcel within an intent sent to system service. An example of exploitation is through the finalize method of android.os.BinderProxy.
Recommendations For Android versions prior to 5.0.0, update to version 5.0.0 or later to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-7911

Affected Products

Android