PT-2016-1830 · Google · Android+1
Abhishek Arya
+2
·
Published
2016-05-09
·
Updated
2016-05-09
·
CVE-2016-2454
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Android versions prior to 2016-05-01 on Nexus 5 devices
Description
The issue is related to insufficient input validation in the Qualcomm hardware video codec. This can be exploited by a remote attacker to cause a denial of service, resulting in a device reboot, by using a specially crafted file. No information is provided about the estimated number of potentially affected devices or real-world incidents.
Recommendations
For Android versions prior to 2016-05-01 on Nexus 5 devices, update the operating system to a version released after 2016-05-01 to resolve the issue.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android
Nexus 5