Multiple integer overflows in libeffects in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 allow attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, related to EffectBundle.cpp and EffectReverb.cpp, aka internal bug 26347509.
Vector
NETWORK
Complexity
MEDIUM
Authentication
NONE
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE
Google Android Operating System 4.2.2
Google Android Operating System 4.3.1
Google Android Operating System 4.2 (Jelly Bean)
Google Android 5.1 (not an official CPE)
Google Android 6.0 (not an official CPE)
Google Android Operating System 4.3
Google Android Operating System 4.4
Google Android 5.0.1 (not an official CPE)
Google Android 5.1.0 (not an official CPE)
Google Android 5.0.2 (not an official CPE)
Google Android 5.1.1 (not an official CPE)
Google Android Operating System 4.0.2
Google Android Operating System 4.0.1
Google Android Operating System 4.0.3
Google Android Operating System 4.1.2
Google Android Operating System 4.2.1
Google Android Operating System 4.4.2
Google Android Operating System 4.4.1
Google Android Operating System 4.4.3
Google Android 6.0.1 (not an official CPE)
Google Android Operating System 4.0.4
Google Android Operating System 5.0
Google Android Operating System 4.1
Google Android Operating System 4.0
Advisory | Patch | Confirmed | Link |
---|---|---|---|
http://source.android.com/security/bulletin/2016-03-01.h... | |||
84268 | |||
https://android.googlesource.com/platform/frameworks/av/... |