CVE-2016-0811
published 2016-02-07CVE-2016-0811: Integer overflow in the BnCrypto::onTransact function in media/libmedia/ICrypto.cpp in libmediaplayerservice in Android 6.x before 2016-02-01 allows attackers…
PriorityP335high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
0.68%
48.6th percentile
Integer overflow in the BnCrypto::onTransact function in media/libmedia/ICrypto.cpp in libmediaplayerservice in Android 6.x before 2016-02-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, by triggering an improper size calculation, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 25800375.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:C/I:N/A:N
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2016-0811: Android Security Bulletin 2016-02-01
CVE: CVE-2016-0811
Severity: HIGH
Affected AOSP versions: 6
vendor_android·2016-02-01·CVSS 7.5
CVE-2016-0811 [HIGH] CVE-2016-0811: Android Security Bulletin 2016-02-01
CVE: CVE-2016-0811
Severity: HIGH
Affected AOSP versions: 6
Android Security Bulletin 2016-02-01
CVE: CVE-2016-0811
Severity: HIGH
Affected AOSP versions: 6.0, 6.0.1
GHSA
GHSA-p7q5-gg3f-3p83: Integer overflow in the BnCrypto::onTransact function in media/libmedia/ICrypto
ghsa_unreviewed·2022-05-17
CVE-2016-0811 [HIGH] CWE-200 GHSA-p7q5-gg3f-3p83: Integer overflow in the BnCrypto::onTransact function in media/libmedia/ICrypto
Integer overflow in the BnCrypto::onTransact function in media/libmedia/ICrypto.cpp in libmediaplayerservice in Android 6.x before 2016-02-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, by triggering an improper size calculation, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 25800375.
OSV
CVE-2016-0811: Integer overflow in the BnCrypto::onTransact function in media/libmedia/ICrypto
osv·2016-02-07·CVSS 7.5
CVE-2016-0811 [HIGH] CVE-2016-0811: Integer overflow in the BnCrypto::onTransact function in media/libmedia/ICrypto
Integer overflow in the BnCrypto::onTransact function in media/libmedia/ICrypto.cpp in libmediaplayerservice in Android 6.x before 2016-02-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, by triggering an improper size calculation, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 25800375.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://source.android.com/security/bulletin/2016-02-01.htmlhttps://android.googlesource.com/platform%2Fframeworks%2Fav/+/22f824feac43d5758f9a70b77f2aca840ba62c3bhttp://source.android.com/security/bulletin/2016-02-01.htmlhttps://android.googlesource.com/platform%2Fframeworks%2Fav/+/22f824feac43d5758f9a70b77f2aca840ba62c3b
2016-02-07
Published