CVE-2016-6702Improper Access Control in INC Android

Severity
7.8HIGHNVD
OSV5.9
EPSS
0.4%
top 37.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 25
Latest updateMay 17

Description

A remote code execution vulnerability in libjpeg in Android 4.x before 4.4.4, 5.0.x before 5.0.2, and 5.1.x before 5.1.1 could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses libjpeg. Android ID: A-30259087.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

NVDgoogle/android20 versions+19
CVEListV5google_inc/androidAndroid-4.4.4, Android-5.0.2, Android-5.1.1+2

🔴Vulnerability Details

3
GHSA
GHSA-g9hh-j62q-7jrm: A remote code execution vulnerability in libjpeg in Android 42022-05-17
OSV
CVE-2016-6702: A remote code execution vulnerability in libjpeg in Android 42016-11-25
OSV
expat vulnerabilities2016-06-20

📋Vendor Advisories

2
Android
CVE-2016-6702: Android Security Bulletin 2016-11-01 CVE: CVE-2016-6702 Severity: HIGH Affected AOSP versions: 42016-11-01
Debian
CVE-2016-6702: libjpeg-turbo - A remote code execution vulnerability in libjpeg in Android 4.x before 4.4.4, 5....2016

💬Community

1
Bugzilla
CVE-2012-6702 expat: Using XML_Parse before rand() results into non-random output2016-03-21