PT-2016-1580 · Google · Android

Heisecode

+1

·

Published

2016-03-12

·

Updated

2016-11-28

·

CVE-2016-0828

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android versions prior to 5.1.1 LMY49H Android 6.x versions prior to 2016-03-01
Description The issue exists due to the lack of initialization of a certain type of variable in the BnGraphicBufferConsumer::onTransact function. This allows a remote attacker to bypass protection mechanisms or obtain confidential information by triggering an ATTACH BUFFER action.
Recommendations For Android versions prior to 5.1.1 LMY49H, update to version 5.1.1 LMY49H or later. For Android 6.x versions prior to 2016-03-01, update to a version released after 2016-03-01. As a temporary workaround, consider restricting access to the BnGraphicBufferConsumer::onTransact function until a patch is available.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-00881
CVE-2016-0828

Affected Products

Android