PT-2020-7967 · Samsung · Samsung Mobile Devices

Published

2020-04-07

·

Updated

2020-04-09

·

CVE-2016-11038

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Samsung mobile devices with software through 2016-04-05
Description: An issue was discovered where the Jack audio service doesn't implement access control for shared memory, leading to arbitrary code execution or privilege escalation.
Recommendations: For Samsung mobile devices with software through 2016-04-05, update the software to a version released after 2016-04-05 to resolve the issue. As a temporary workaround, consider restricting access to the Jack audio service to minimize the risk of exploitation.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-11038

Affected Products

Samsung Mobile Devices