PT-2016-7719 · Google · Android+1
Published
2016-11-11
·
Updated
2016-11-29
·
CVE-2016-9277
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Android versions 4.4 through 5.1 on Samsung Note devices
Description
The issue is related to an integer overflow in SystemUI, which can be exploited by attackers to cause a denial of service, resulting in a UI restart. This can be achieved through vectors involving APIs and an activity that computes an out-of-bounds array index.
Recommendations
For Android versions 4.4 through 5.1 on Samsung Note devices, consider applying configuration changes to restrict access to the affected SystemUI component until a patch is available. As a temporary workaround, disabling the affected activity that computes the out-of-bounds array index may help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android
Systemui