CVE-2016-2414
published 2016-04-18CVE-2016-2414: The Minikin library in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider negative size values in font data…
PriorityP423medium6.2CVSS 3.0
AVLACLPRNUINSUCNINAH
EPSS
0.40%
33.3th percentile
The Minikin library in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider negative size values in font data, which allows remote attackers to cause a denial of service (memory corruption and reboot loop) via a crafted font, aka internal bug 26413177.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.06.2MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2p8f-fx67-q665: The Minikin library in Android 5
ghsa_unreviewed·2022-05-17
CVE-2016-2414 [MEDIUM] CWE-20 GHSA-2p8f-fx67-q665: The Minikin library in Android 5
The Minikin library in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider negative size values in font data, which allows remote attackers to cause a denial of service (memory corruption and reboot loop) via a crafted font, aka internal bug 26413177.
OSV
CVE-2016-2414: The Minikin library in Android 5
osv·2016-04-18·CVSS 6.2
CVE-2016-2414 [MEDIUM] CVE-2016-2414: The Minikin library in Android 5
The Minikin library in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider negative size values in font data, which allows remote attackers to cause a denial of service (memory corruption and reboot loop) via a crafted font, aka internal bug 26413177.
No detection rules found.
No public exploits indexed.
Fortinet
Rise of the Funnel Cloud: When Good Clouds Go Bad
blogs_fortinet·2017-08-07
Rise of the Funnel Cloud: When Good Clouds Go Bad
INDUSTRY TRENDS & INSIGHTS
Rise of the Funnel Cloud: When Good Clouds Go Bad
By James Cabe | August 07, 2017
What is a cloud, really?
In the simplest terms, the cloud allows users to store and access data and programs on someone else’s hardware, usually over the internet, rather than using their local device or network resources. But it is much more than simply offsite storage. It also includes services that allow users to replicate some or all of their local environment, from running applications to designing complex infrastructures. And it needs to be able to scale to lots of users.
Simply put, you do not have a “cloud” unless there is a way to commoditize those services. That means that cloud providers also need some sort of repeatability or automation that enables dynamic scalabili
Fortinet
Unmasking Android Malware: A Deep Dive into a New Rootnik Variant, Part I
blogs_fortinet·2017-07-09
Unmasking Android Malware: A Deep Dive into a New Rootnik Variant, Part I
FORTIGUARD LABS THREAT RESEARCH
Unmasking Android Malware: A Deep Dive into a New Rootnik Variant, Part I
By Kai Lu | July 09, 2017
This past January I performed a deep analysis of an Android rootnik malware variant and posted them to this blog. Since then, I have continued to monitor this Android malware family. In early June, FortiGuard Labs found a new variant of the Android rootnik malware that disguises itself as a legal app. It then uses open-sourced Android root exploit tools to gain root access on an Android device.
To be clear, this malware was NOT found in Google Play. The developer of the malware app repackaged a legal app from Google Play and inserted the malicious codes into it. Both the legal and the repackaged versions of this app use the same package name “net.gotsun.and
Fortinet
Looking Back at Fortinet’s Security Research and Vulnerability Discoveries
blogs_fortinet·2017-02-21
Looking Back at Fortinet’s Security Research and Vulnerability Discoveries
FORTIGUARD LABS THREAT RESEARCH
Looking Back at Fortinet’s Security Research and Vulnerability Discoveries
By Peixue Li | February 21, 2017
In an effort to provide more proactive protections in Fortinet products and to more effectively identify and defeat network threats, the Fortinet security research team works on discovering potential threats in popular products. As a result, over the past year we have discovered 84 vulnerabilities that have been reported to their respective vendors as part of our responsible vulnerability disclosure process. Fortinet protections against these discoveries were released to Fortinet products at the same time these vulnerabilities were reported to their vendors. As a result, Fortinet products have been able to proactively protect Fortinet customers’ netw
Fortinet
Deep Analysis of Android Rootnik Malware Using Advanced Anti-Debug and Anti-Hook, Part I: Debugging in The Scope of Native Layer
blogs_fortinet·2017-01-26
Deep Analysis of Android Rootnik Malware Using Advanced Anti-Debug and Anti-Hook, Part I: Debugging in The Scope of Native Layer
FORTIGUARD LABS THREAT RESEARCH
Deep Analysis of Android Rootnik Malware Using Advanced Anti-Debug and Anti-Hook, Part I: Debugging in The Scope of Native Layer
By Kai Lu | January 26, 2017
Recently, we found a new Android rootnik malware which uses open-sourced Android root exploit tools and the MTK root scheme from the dashi root tool to gain root access on an Android device. The malware disguises itself as a file helper app and then uses very advanced anti-debug and anti-hook techniques to prevent it from being reverse engineered. It also uses a multidex scheme to load a secondary dex file. After successfully gaining root privileges on the device, the rootnik malware can perform several malicious behaviors, including app and ad promotion, pushing porn, creating shortcuts on the home s
Fortinet
Analysis of OpenSSL Large Message Size Handling Use After Free (CVE-2016-6309)
blogs_fortinet·2016-10-12·CVSS 5.9
CVE-2016-6309 [MEDIUM] Analysis of OpenSSL Large Message Size Handling Use After Free (CVE-2016-6309)
FORTIGUARD LABS THREAT RESEARCH
Analysis of OpenSSL Large Message Size Handling Use After Free (CVE-2016-6309)
By Dehui Yin | October 12, 2016
OpenSSL released an emergency security update shortly after a patch was issued a few weeks ago. This security update addresses a critical Use After Free vulnerability introduced by the updated code that revised to resolve the earlier low severity vulnerability CVE-2016-6307.
This critical Use After Free vulnerability (CVE-2016-6309) is caused by an error that occurs when relocating a message with an overlarge message size greater than 16k. Remote attackers may access the freed buffer to crash, or potentially even execute arbitrary code on vulnerable systems.
This Use After Free vulnerability only affects OpenSSL version 1.1.0a. In this report we
Fortinet
Analysis of CVE-2016-2414 - Out-of-Bound Write Denial of Service Vulnerability in Android Minikin Library
blogs_fortinet·2016-04-13·CVSS 6.2
CVE-2016-2414 [MEDIUM] Analysis of CVE-2016-2414 - Out-of-Bound Write Denial of Service Vulnerability in Android Minikin Library
FORTIGUARD LABS THREAT RESEARCH
Analysis of CVE-2016-2414 - Out-of-Bound Write Denial of Service Vulnerability in Android Minikin Library
By Kai Lu | April 13, 2016
Google fixed a denial of service vulnerability in Minikin library (CVE-2016-2414) with the Android patches of this month. I reported this vulnerability to Google in early March, 2016 and Google confirmed it was a duplicated report of bug 26413177 which had been reported by another researcher in November, 2015.
In this blog, we will provide an in-depth analysis of this vulnerability. It exists because the Minikin library fails to parse .TTF font files correctly. As a result, it could allow a local attacker to temporarily block access to an affected Android device. The attacker could have an untrusted font file loaded, causing
Fortinet
Haystacks and Needles: IoT Security through "Pico"-Segmentation
blogs_fortinet·2016-02-23
Haystacks and Needles: IoT Security through "Pico"-Segmentation
INDUSTRY TRENDS & INSIGHTS
Haystacks and Needles: IoT Security through "Pico"-Segmentation
By Tyson Macaulay | February 23, 2016
Over the past year or so we’ve heard lots about segmentation and micro-segmentation as new ways to build effective cyber defences in enterprise networks and data centres… but is it enough? Can we delve even deeper? I believe there may be a third leg to the segmentation stool: pico-segmentation.
Before I explain, I think it worth a moment or two to talk about the first two legs of the stool. Segmentation or network segmentation is really all about controlling the flow of traffic from one domain of control to another domain of control. These segments, or stovepipes are architected so that cross-domain communications can not be illicitly established. For example:
Fortinet
Analysis of CVE-2016-0059 - Microsoft IE Information Disclosure Vulnerability Discovered by Fortinet
blogs_fortinet·2016-02-19·CVSS 7.8
CVE-2016-0059 [HIGH] Analysis of CVE-2016-0059 - Microsoft IE Information Disclosure Vulnerability Discovered by Fortinet
FORTIGUARD LABS THREAT RESEARCH
Analysis of CVE-2016-0059 - Microsoft IE Information Disclosure Vulnerability Discovered by Fortinet
By Kai Lu | February 19, 2016
Summary
This month Microsoft patched two vulnerabilities which were discovered and reported by me, one is an information disclosure vulnerability in Internet Explorer (IE) (CVE-2016-0059 in MS16-009), the other is a memory corruption vulnerability in Microsoft Office (CVE-2016-0055 in MS16-015). In this blog, we will provide in-depth analysis of CVE-2016-0059. The vulnerability exists because Microsoft Hyperlink Object Library improperly discloses the contents of its memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit the vulnerability,
Fortinet
"Fractalizing" Security
blogs_fortinet·2016-01-26
"Fractalizing" Security
INDUSTRY TRENDS & INSIGHTS
"Fractalizing" Security
By Tyson Macaulay | January 26, 2016
Most people are familiar with fractals, if not by name but by appearance. Wikipedia defines a fractal as “…a natural phenomenon or a mathematical set that exhibits a repeating pattern that displays at every scale.” Perhaps the most famous example of a fractal is the Mandelbrot set, which is shown below.
Figure 1: The Mandelbrot Set. Image Copyright Wikimedia - Creative Commons.
The key takeaway here is that no matter how far you “zoom in” on the fractal, the patterns you see will repeat themselves forever. You can view an animated example of the Mandelbrot set here: https://www.youtube.com/watch?v=PD2XgQOyCCk
With that being said, how can we apply fractals to the world of network security? Can we
http://source.android.com/security/bulletin/2016-04-02.htmlhttps://android.googlesource.com/platform/frameworks/minikin/+/ca8ac8acdad662230ae37998c6c4091bb39402b6https://android.googlesource.com/platform/frameworks/minikin/+/f4785aa1947b8d22d5b19559ef1ca526d98e0e73https://code.google.com/p/android/issues/detail?id=192618http://source.android.com/security/bulletin/2016-04-02.htmlhttps://android.googlesource.com/platform/frameworks/minikin/+/ca8ac8acdad662230ae37998c6c4091bb39402b6https://android.googlesource.com/platform/frameworks/minikin/+/f4785aa1947b8d22d5b19559ef1ca526d98e0e73https://code.google.com/p/android/issues/detail?id=192618
2016-04-18
Published