PT-2020-7967 · Samsung · Samsung Mobile Devices
Published
2020-04-07
·
Updated
2020-04-09
·
CVE-2016-11038
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Samsung mobile devices with software through 2016-04-05
Description:
An issue was discovered where the Jack audio service doesn't implement access control for shared memory, leading to arbitrary code execution or privilege escalation.
Recommendations:
For Samsung mobile devices with software through 2016-04-05, update the software to a version released after 2016-04-05 to resolve the issue. As a temporary workaround, consider restricting access to the Jack audio service to minimize the risk of exploitation.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Samsung Mobile Devices