CVE-2016-6704
published 2016-11-25CVE-2016-6704: An elevation of privilege vulnerability in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0…
PriorityP336high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
0.91%
56.0th percentile
An elevation of privilege vulnerability in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Android ID: A-30229821.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | >= 4.0 < 4.4.4 | 4.4.4 | |
| android | >= 5.0 < 5.0.2 | 5.0.2 | |
| android | >= 5.1 < 5.1.1 | 5.1.1 | |
| android | 6.0 – 6.0.1 | — | |
| google_inc | android | — | — |
| google_inc | android | — | — |
| google_inc | android | — | — |
| google_inc | android | — | — |
| google_inc | android | — | — |
| google_inc | android | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cq4q-8ww6-c3pq: An elevation of privilege vulnerability in Mediaserver in Android 4
ghsa_unreviewed·2022-05-14
CVE-2016-6704 [HIGH] GHSA-cq4q-8ww6-c3pq: An elevation of privilege vulnerability in Mediaserver in Android 4
An elevation of privilege vulnerability in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Android ID: A-30229821.
OSV
CVE-2016-6704: An elevation of privilege vulnerability in Mediaserver in Android 4
osv·2016-11-25·CVSS 7.8
CVE-2016-6704 [HIGH] CVE-2016-6704: An elevation of privilege vulnerability in Mediaserver in Android 4
An elevation of privilege vulnerability in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Android ID: A-30229821.
Android
CVE-2016-6704: Android Security Bulletin 2016-11-01
CVE: CVE-2016-6704
Severity: HIGH
Affected AOSP versions: 4
vendor_android·2016-11-01·CVSS 7.8
CVE-2016-6704 [HIGH] CVE-2016-6704: Android Security Bulletin 2016-11-01
CVE: CVE-2016-6704
Severity: HIGH
Affected AOSP versions: 4
Android Security Bulletin 2016-11-01
CVE: CVE-2016-6704
Severity: HIGH
Affected AOSP versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0
References: A-30229821
[2]
[3]
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9793 kernel: Signed overflow for SO_{SND|RCV}BUFFORCE
bugzilla·2016-12-06·CVSS 7.8
CVE-2016-9793 [HIGH] CVE-2016-9793 kernel: Signed overflow for SO_{SND|RCV}BUFFORCE
CVE-2016-9793 kernel: Signed overflow for SO_{SND|RCV}BUFFORCE
A flaw was found in the Linux kernels implementation of setsockopt for the SO_{SND|RCV}BUFFORCE setsockopt() system call. Users with non-namespace CAP_NET_ADMIN are able to trigger this call and create a situation in which the sockets sendbuff data size could be negative.
This could adversely affect memory allocations and create situations where the system could crash or cause memory corruption.
This situation affects SO_SNDBUFF and SO_RCVBUFF similarly as shown in CVE-2012-6704.
Upstream patch:
https://github.com/torvalds/linux/commit/b98b0bc8c431e3ceb4b26b0dfc8db509518fb290
CVE assignment:
http://seclists.org/oss-sec/2016/q4/574
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 140201
Bugzilla
CVE-2012-6704 kernel: Signed overflows in SO_{SND|RCV}BUF in sock_setsockopt()
bugzilla·2016-12-06·CVSS 7.8
CVE-2012-6704 [HIGH] CVE-2012-6704 kernel: Signed overflows in SO_{SND|RCV}BUF in sock_setsockopt()
CVE-2012-6704 kernel: Signed overflows in SO_{SND|RCV}BUF in sock_setsockopt()
A flaw was found in the Linux kernels implementation of setsockopt for the SO_{SND|RCV}BUF setsockopt() system call. Users with non-namespace CAP_NET_ADMIN are able to trigger this call and create a situation in which the sockets sendbuff data size could be negative.
This could adversely affect memory allocations and create situations where the system could crash or cause memory corruption.
This situation affects SO_SNDBUFF and SO_RCVBUFF similarly as shown in CVE-2016-9793.
Upstream patch:
https://github.com/torvalds/linux/commit/82981930125abfd39d7c8378a9cfdf5e1be2002b
CVE assignment:
http://seclists.org/oss-sec/2016/q4/574
Discussion:
Statement:
This issue does not affect the kernels as shipping wit
http://www.securityfocus.com/bid/94134https://source.android.com/security/bulletin/2016-11-01.htmlhttps://source.android.com/security/bulletin/2016-12-01.htmlhttp://www.securityfocus.com/bid/94134https://source.android.com/security/bulletin/2016-11-01.htmlhttps://source.android.com/security/bulletin/2016-12-01.html
2016-11-25
Published