CVE-2016-0811 Information
Feb 14, 2021
cve
Description
Integer overflow in the BnCrypto::onTransact function in media/libmedia/ICrypto.cpp in libmediaplayerservice in Android 6.x before 2016-02-01 allows attackers to obtain sensitive information and consequently bypass an unspecified protection mechanism by triggering an improper size calculation as demonstrated by obtaining Signature or SignatureOrSystem access aka internal bug 25800375.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Reference
http://source.android.com/security/bulletin/2016-02-01.html https://android.googlesource.com/platform2Fframeworks2Fav/+/22f824feac43d5758f9a70b77f2aca840ba62c3b
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
7.5
Share on: