CVE-2015-3845
published 2015-10-01CVE-2015-3845: The Parcel::appendFrom function in libs/binder/Parcel.cpp in Binder in Android before 5.1.1 LMY48M does not consider parcel boundaries during identification of…
PriorityP426medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
0.61%
45.7th percentile
The Parcel::appendFrom function in libs/binder/Parcel.cpp in Binder in Android before 5.1.1 LMY48M does not consider parcel boundaries during identification of binder objects in an append operation, which allows attackers to obtain a different application's privileges via a crafted application, aka internal bug 17312693.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | <= 5.1 | — | |
| android | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2015-3845: Android Security Bulletin 2015-09-01
CVE: CVE-2015-3845
Severity: HIGH
Affected AOSP versions: 5
vendor_android·2015-09-01·CVSS 6.8
CVE-2015-3845 [MEDIUM] CVE-2015-3845: Android Security Bulletin 2015-09-01
CVE: CVE-2015-3845
Severity: HIGH
Affected AOSP versions: 5
Android Security Bulletin 2015-09-01
CVE: CVE-2015-3845
Severity: HIGH
Affected AOSP versions: 5.1 and below
GHSA
GHSA-54x8-qj95-fq96: The Parcel::appendFrom function in libs/binder/Parcel
ghsa_unreviewed·2022-05-17
CVE-2015-3845 [MEDIUM] GHSA-54x8-qj95-fq96: The Parcel::appendFrom function in libs/binder/Parcel
The Parcel::appendFrom function in libs/binder/Parcel.cpp in Binder in Android before 5.1.1 LMY48M does not consider parcel boundaries during identification of binder objects in an append operation, which allows attackers to obtain a different application's privileges via a crafted application, aka internal bug 17312693.
OSV
CVE-2015-3845: The Parcel::appendFrom function in libs/binder/Parcel
osv·2015-10-01·CVSS 6.8
CVE-2015-3845 [MEDIUM] CVE-2015-3845: The Parcel::appendFrom function in libs/binder/Parcel
The Parcel::appendFrom function in libs/binder/Parcel.cpp in Binder in Android before 5.1.1 LMY48M does not consider parcel boundaries during identification of binder objects in an append operation, which allows attackers to obtain a different application's privileges via a crafted application, aka internal bug 17312693.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://android.googlesource.com/platform/frameworks/native/+/e68cbc3e9e66df4231e70efa3e9c41abc12aea20https://groups.google.com/forum/message/raw?msg=android-security-updates/1M7qbSvACjo/Y7jewiW1AwAJhttps://android.googlesource.com/platform/frameworks/native/+/e68cbc3e9e66df4231e70efa3e9c41abc12aea20https://groups.google.com/forum/message/raw?msg=android-security-updates/1M7qbSvACjo/Y7jewiW1AwAJ
2015-10-01
Published