CVE-2015-6640
published 2016-01-06CVE-2015-6640: The prctl_set_vma_anon_name function in kernel/sys.c in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 does not ensure that only one vma is accessed in…
PriorityP433high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
0.73%
50.7th percentile
The prctl_set_vma_anon_name function in kernel/sys.c in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 does not ensure that only one vma is accessed in a certain update action, which allows attackers to gain privileges or cause a denial of service (vma list corruption) via a crafted application, aka internal bug 20017123.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-82j5-hvq2-xqxg: The prctl_set_vma_anon_name function in kernel/sys
ghsa_unreviewed·2022-05-17
CVE-2015-6640 [HIGH] GHSA-82j5-hvq2-xqxg: The prctl_set_vma_anon_name function in kernel/sys
The prctl_set_vma_anon_name function in kernel/sys.c in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 does not ensure that only one vma is accessed in a certain update action, which allows attackers to gain privileges or cause a denial of service (vma list corruption) via a crafted application, aka internal bug 20017123.
OSV
CVE-2015-6640: The prctl_set_vma_anon_name function in kernel/sys
osv·2016-01-06·CVSS 7.8
CVE-2015-6640 [HIGH] CVE-2015-6640: The prctl_set_vma_anon_name function in kernel/sys
The prctl_set_vma_anon_name function in kernel/sys.c in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 does not ensure that only one vma is accessed in a certain update action, which allows attackers to gain privileges or cause a denial of service (vma list corruption) via a crafted application, aka internal bug 20017123.
Android
CVE-2015-6640: Android Security Bulletin 2016-01-01
CVE: CVE-2015-6640
Severity: CRITICAL
Affected AOSP versions: 4
vendor_android·2016-01-01·CVSS 7.8
CVE-2015-6640 [HIGH] CVE-2015-6640: Android Security Bulletin 2016-01-01
CVE: CVE-2015-6640
Severity: CRITICAL
Affected AOSP versions: 4
Android Security Bulletin 2016-01-01
CVE: CVE-2015-6640
Severity: CRITICAL
Affected AOSP versions: 4.4.4, 5.0, 5.1.1, 6.0
No detection rules found.
Nuclei
ResourceSpace - Local File inclusion
nuclei·CVSS 7.5
CVE-2015-3648 [HIGH] ResourceSpace - Local File inclusion
ResourceSpace - Local File inclusion
ResourceSpace is prone to a local file-inclusion vulnerability because it fails to sufficiently sanitize user-supplied input.
Template:
id: CVE-2015-3648
info:
name: ResourceSpace - Local File inclusion
author: pikpikcu
severity: high
description: ResourceSpace is prone to a local file-inclusion vulnerability because it fails to sufficiently sanitize user-supplied input.
impact: |
An attacker can exploit this vulnerability to read sensitive files, execute arbitrary code, or launch further attacks.
remediation: |
Upgrade to the latest version of ResourceSpace to fix the local file inclusion vulnerability.
reference:
- https://vulners.com/cve/CVE-2015-3648/
- http://svn.montala.com/websvn/revision.php?repname=ResourceSpace&path=%2F&rev=6640&peg=6738
-
No writeups or analysis indexed.
http://source.android.com/security/bulletin/2016-01-01.htmlhttp://www.securitytracker.com/id/1034592https://android.googlesource.com/kernel%2Fcommon/+/69bfe2d957d903521d32324190c2754cb073be15http://source.android.com/security/bulletin/2016-01-01.htmlhttp://www.securitytracker.com/id/1034592https://android.googlesource.com/kernel%2Fcommon/+/69bfe2d957d903521d32324190c2754cb073be15
2016-01-06
Published