PT-2016-3524 · Google · Android
Published
2016-07-11
·
Updated
2016-11-28
·
CVE-2014-9782
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Android versions prior to 2016-07-05
Description
The issue concerns a lack of validation for
direction and step parameters in the msm actuator.c file, part of the Qualcomm components in Android. This allows attackers to gain privileges via a crafted application.Recommendations
For Android versions prior to 2016-07-05, consider restricting access to the
msm actuator.c file until a patch is available. As a temporary workaround, avoid using the direction and step parameters in affected applications until the issue is resolved.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android