CVE-2011-3874
published 2012-01-27CVE-2011-3874: Stack-based buffer overflow in libsysutils in Android 2.2.x through 2.2.2 and 2.3.x through 2.3.6 allows user-assisted remote attackers to execute arbitrary…
PriorityP343critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
12.51%
95.7th percentile
Stack-based buffer overflow in libsysutils in Android 2.2.x through 2.2.2 and 2.3.x through 2.3.6 allows user-assisted remote attackers to execute arbitrary code via an application that calls the FrameworkListener::dispatchCommand method with the wrong number of arguments, as demonstrated by zergRush to trigger a use-after-free error.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://code.google.com/p/android/issues/detail?id=21681http://www.openwall.com/lists/oss-security/2011/11/08/3http://www.openwall.com/lists/oss-security/2011/11/08/4http://www.openwall.com/lists/oss-security/2011/11/10/1https://github.com/revolutionary/zergRush/blob/master/zergRush.chttp://code.google.com/p/android/issues/detail?id=21681http://www.openwall.com/lists/oss-security/2011/11/08/3http://www.openwall.com/lists/oss-security/2011/11/08/4http://www.openwall.com/lists/oss-security/2011/11/10/1https://github.com/revolutionary/zergRush/blob/master/zergRush.c
2012-01-27
Published