CVE-2016-0818
published 2016-03-12CVE-2016-0818: The caching functionality in the TrustManagerImpl class in TrustManagerImpl.java in Conscrypt in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x…
PriorityP426medium5.9CVSS 3.0
AVNACHPRNUINSUCNIHAN
EPSS
0.27%
18.8th percentile
The caching functionality in the TrustManagerImpl class in TrustManagerImpl.java in Conscrypt in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 mishandles the distinction between an intermediate CA and a trusted root CA, which allows man-in-the-middle attackers to spoof servers by leveraging access to an intermediate CA to issue a certificate, aka internal bug 26232830.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2016-0818: Android Security Bulletin 2016-03-01
CVE: CVE-2016-0818
Severity: CRITICAL
Affected AOSP versions: 4
vendor_android·2016-03-01·CVSS 5.9
CVE-2016-0818 [MEDIUM] CVE-2016-0818: Android Security Bulletin 2016-03-01
CVE: CVE-2016-0818
Severity: CRITICAL
Affected AOSP versions: 4
Android Security Bulletin 2016-03-01
CVE: CVE-2016-0818
Severity: CRITICAL
Affected AOSP versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1
GHSA
GHSA-gfmm-3f49-2hrh: The caching functionality in the TrustManagerImpl class in TrustManagerImpl
ghsa_unreviewed·2022-05-17
CVE-2016-0818 [MEDIUM] GHSA-gfmm-3f49-2hrh: The caching functionality in the TrustManagerImpl class in TrustManagerImpl
The caching functionality in the TrustManagerImpl class in TrustManagerImpl.java in Conscrypt in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 mishandles the distinction between an intermediate CA and a trusted root CA, which allows man-in-the-middle attackers to spoof servers by leveraging access to an intermediate CA to issue a certificate, aka internal bug 26232830.
OSV
CVE-2016-0818: The caching functionality in the TrustManagerImpl class in TrustManagerImpl
osv·2016-03-12·CVSS 5.9
CVE-2016-0818 [MEDIUM] CVE-2016-0818: The caching functionality in the TrustManagerImpl class in TrustManagerImpl
The caching functionality in the TrustManagerImpl class in TrustManagerImpl.java in Conscrypt in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 mishandles the distinction between an intermediate CA and a trusted root CA, which allows man-in-the-middle attackers to spoof servers by leveraging access to an intermediate CA to issue a certificate, aka internal bug 26232830.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://source.android.com/security/bulletin/2016-03-01.htmlhttp://www.securityfocus.com/bid/84245https://android.googlesource.com/platform/external/conscrypt/+/4c9f9c2201116acf790fca25af43995d29980ee0https://android.googlesource.com/platform/external/conscrypt/+/c4ab1b959280413fb11bf4fd7f6b4c2ba38bd779http://source.android.com/security/bulletin/2016-03-01.htmlhttp://www.securityfocus.com/bid/84245https://android.googlesource.com/platform/external/conscrypt/+/4c9f9c2201116acf790fca25af43995d29980ee0https://android.googlesource.com/platform/external/conscrypt/+/c4ab1b959280413fb11bf4fd7f6b4c2ba38bd779
2016-03-12
Published