PT-2016-2474 · Google · Android

Guang Gong

+1

·

Published

2016-07-11

·

Updated

2016-07-11

·

CVE-2016-3744

CVSS v3.1

7.5

High

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions prior to 4.4.4 Android 5.0.x versions prior to 5.0.2 Android 5.1.x versions prior to 5.1.1 Android 6.x versions prior to 2016-07-01
Description The issue is caused by a buffer overflow in the create pbuf function in the Bluetooth component of Android. This allows remote attackers to gain privileges via a crafted pairing operation.
Recommendations For Android versions prior to 4.4.4, update to version 4.4.4 or later. For Android 5.0.x versions prior to 5.0.2, update to version 5.0.2 or later. For Android 5.1.x versions prior to 5.1.1, update to version 5.1.1 or later. For Android 6.x versions prior to 2016-07-01, update to a version released after 2016-07-01.

Fix

Race Condition

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-01865
CVE-2016-3744

Affected Products

Android