PT-2016-1584 · Google · Android+1

Anestis Bechtsoudis

+1

·

Published

2016-03-12

·

Updated

2016-11-28

·

CVE-2016-0824

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android 6.x before 2016-03-01
Description The issue allows attackers to obtain sensitive information and bypass an unspecified protection mechanism via crafted Bitstream data. This can be achieved by exploiting errors in security settings, potentially granting access to confidential information or allowing the bypassing of protection mechanisms.
Recommendations For Android 6.x before 2016-03-01, update the system to a version released after 2016-03-01 to resolve the issue. As a temporary workaround, consider restricting the use of libstagefright until a patch is available. Avoid using crafted Bitstream data in the affected system until the issue is resolved.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-00885
CVE-2016-0824

Affected Products

Android
Libstagefright