CVE-2016-2419
published 2016-04-18CVE-2016-2419: media/libmedia/IDrm.cpp in mediaserver in Android 6.x before 2016-04-01 does not initialize a certain key-request data structure, which allows attackers to…
PriorityP338critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
0.80%
53.0th percentile
media/libmedia/IDrm.cpp in mediaserver in Android 6.x before 2016-04-01 does not initialize a certain key-request data structure, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified protection mechanism, via unspecified vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26323455.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mj56-gq69-pp97: media/libmedia/IDrm
ghsa_unreviewed·2022-05-17
CVE-2016-2419 [CRITICAL] GHSA-mj56-gq69-pp97: media/libmedia/IDrm
media/libmedia/IDrm.cpp in mediaserver in Android 6.x before 2016-04-01 does not initialize a certain key-request data structure, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified protection mechanism, via unspecified vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26323455.
OSV
CVE-2016-2419: media/libmedia/IDrm
osv·2016-04-18·CVSS 9.8
CVE-2016-2419 [CRITICAL] CVE-2016-2419: media/libmedia/IDrm
media/libmedia/IDrm.cpp in mediaserver in Android 6.x before 2016-04-01 does not initialize a certain key-request data structure, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified protection mechanism, via unspecified vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26323455.
Suricata
ET EXPLOIT_KIT Terror EK CVE-2015-2419 Exploit
suricata·2017-04-04·CVSS 8.8
CVE-2016-0189 [HIGH] ET EXPLOIT_KIT Terror EK CVE-2015-2419 Exploit
ET EXPLOIT_KIT Terror EK CVE-2015-2419 Exploit
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT_KIT Terror EK CVE-2015-2419 Exploit"; flow:established,to_client; file.data; content:"EB125831C966B9"; nocase; content:"05498034088485C975F7FFE0E8E9FFFFFFD10D61074028D7D5D3B544E0"; distance:2; within:58; nocase; reference:cve,2016-0189; classtype:exploit-kit; sid:2024170; rev:3; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2017_04_04, cve CVE_2016_0189, deployment Perimeter, malware_family Exploit_Kit_Terror, performance_impact Low, confidence High, signature_severity Major, tag Exploit_Kit_Terror, tag CISA_KEV, updated_at 2024_03_14;)
No public exploits indexed.
http://source.android.com/security/bulletin/2016-04-02.htmlhttps://android.googlesource.com/platform/frameworks/av/+/5a856f2092f7086aa0fea9ae06b9255befcdcd34http://source.android.com/security/bulletin/2016-04-02.htmlhttps://android.googlesource.com/platform/frameworks/av/+/5a856f2092f7086aa0fea9ae06b9255befcdcd34
2016-04-18
Published