CVE-2016-5857
published 2017-03-20CVE-2016-5857: The Qualcomm SPCom driver in Android before 7.0 allows local users to execute arbitrary code within the context of the kernel via a crafted application, aka…
PriorityP432high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
0.26%
17.7th percentile
The Qualcomm SPCom driver in Android before 7.0 allows local users to execute arbitrary code within the context of the kernel via a crafted application, aka Android internal bug 34386529 and Qualcomm internal bug CR#1094140.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | <= 6.0.1 | — | |
| android | — | — | |
| android | — | — | |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-678x-4w6h-qm5x: The Qualcomm SPCom driver in Android before 7
ghsa_unreviewed·2022-05-17
CVE-2016-5857 [HIGH] GHSA-678x-4w6h-qm5x: The Qualcomm SPCom driver in Android before 7
The Qualcomm SPCom driver in Android before 7.0 allows local users to execute arbitrary code within the context of the kernel via a crafted application, aka Android internal bug 34386529 and Qualcomm internal bug CR#1094140.
GHSA
GHSA-jp4h-829h-5qxc: Drivers/soc/qcom/spcom
ghsa_unreviewed·2022-05-17·CVSS 7.8
CVE-2016-5856 [HIGH] GHSA-jp4h-829h-5qxc: Drivers/soc/qcom/spcom
Drivers/soc/qcom/spcom.c in the Qualcomm SPCom driver in the Android kernel 2017-03-05 allows local users to gain privileges, a different vulnerability than CVE-2016-5857.
OSV
CVE-2016-5856: Drivers/soc/qcom/spcom
osv·2017-04-12·CVSS 7.0
CVE-2016-5856 [HIGH] CVE-2016-5856: Drivers/soc/qcom/spcom
Drivers/soc/qcom/spcom.c in the Qualcomm SPCom driver in the Android kernel 2017-03-05 allows local users to gain privileges, a different vulnerability than CVE-2016-5857.
OSV
CVE-2016-5857: The Qualcomm SPCom driver in Android before 7
osv·2017-03-20·CVSS 7.8
CVE-2016-5857 [HIGH] CVE-2016-5857: The Qualcomm SPCom driver in Android before 7
The Qualcomm SPCom driver in Android before 7.0 allows local users to execute arbitrary code within the context of the kernel via a crafted application, aka Android internal bug 34386529 and Qualcomm internal bug CR#1094140.
Android
CVE-2016-5857: Android Security Bulletin 2017-03-01
CVE: CVE-2016-5857
Severity: HIGH
References: A-34386529
QC-CR#1094140
vendor_android·2017-03-01·CVSS 7.8
CVE-2016-5857 [HIGH] CVE-2016-5857: Android Security Bulletin 2017-03-01
CVE: CVE-2016-5857
Severity: HIGH
References: A-34386529
QC-CR#1094140
Android Security Bulletin 2017-03-01
CVE: CVE-2016-5857
Severity: HIGH
References: A-34386529
QC-CR#1094140
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-5652 CVE-2016-5875 CVE-2016-8331 mingw-libtiff: various flaws [epel-7]
bugzilla·2016-10-27·CVSS 7.0
CVE-2016-5652 [HIGH] CVE-2016-5652 CVE-2016-5875 CVE-2016-8331 mingw-libtiff: various flaws [epel-7]
CVE-2016-5652 CVE-2016-5875 CVE-2016-8331 mingw-libtiff: various flaws [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: add-tracking-bugs]
Bugzilla
CVE-2016-5875 libtiff: PixarLogDecode Heap Buffer Overflow
bugzilla·2016-10-27·CVSS 8.8
CVE-2016-5875 [HIGH] CVE-2016-5875 libtiff: PixarLogDecode Heap Buffer Overflow
CVE-2016-5875 libtiff: PixarLogDecode Heap Buffer Overflow
An exploitable heap based buffer overflow exists in the handling of compressed TIFF images in LibTIFF’s PixarLogDecode api. A crafted TIFF document can lead to a heap based buffer overflow resulting in remote code execution. The vulnerability can be triggered through any user controlled TIFF that is handled by this functionality.
External References:
http://www.talosintelligence.com/reports/TALOS-2016-0205
Discussion:
Created libtiff tracking bugs for this issue:
Affects: fedora-all [bug 1389231]
---
Created mingw-libtiff tracking bugs for this issue:
Affects: fedora-all [bug 1389232]
Affects: epel-7 [bug 1389233]
---
Hi
According to TALOS-2016-0205 the actual CVE ID should be CVE-2016-5875. So is the CVE-2016-5857 alia
Bugzilla
CVE-2016-5652 CVE-2016-5875 CVE-2016-8331 libtiff: various flaws [fedora-all]
bugzilla·2016-10-27·CVSS 7.0
CVE-2016-5652 [HIGH] CVE-2016-5652 CVE-2016-5875 CVE-2016-8331 libtiff: various flaws [fedora-all]
CVE-2016-5652 CVE-2016-5875 CVE-2016-8331 libtiff: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
Bugzilla
CVE-2016-5652 CVE-2016-5875 CVE-2016-8331 mingw-libtiff: various flaws [fedora-all]
bugzilla·2016-10-27·CVSS 7.0
CVE-2016-5652 [HIGH] CVE-2016-5652 CVE-2016-5875 CVE-2016-8331 mingw-libtiff: various flaws [fedora-all]
CVE-2016-5652 CVE-2016-5875 CVE-2016-8331 mingw-libtiff: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versio
2017-03-20
Published