CVE-2016-6711
published 2016-12-13CVE-2016-6711: A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before…
PriorityP419medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
0.83%
53.4th percentile
A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-01 could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Android ID: A-30593765.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libvpx | < libvpx 1.6.1-1 (bookworm) | libvpx 1.6.1-1 (bookworm) |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| webmproject | libvpx | >= 0 < 1.6.1-1 | 1.6.1-1 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv5.5MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r462-m3f4-2jmm: A remote denial of service vulnerability in libvpx in Mediaserver in Android 4
ghsa_unreviewed·2022-05-17
CVE-2016-6711 [HIGH] CWE-20 GHSA-r462-m3f4-2jmm: A remote denial of service vulnerability in libvpx in Mediaserver in Android 4
A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-01 could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Android ID: A-30593765.
OSV
CVE-2016-6711: A remote denial of service vulnerability in libvpx in Mediaserver in Android 4
osv·2016-12-13·CVSS 5.5
CVE-2016-6711 [MEDIUM] CVE-2016-6711: A remote denial of service vulnerability in libvpx in Mediaserver in Android 4
A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-01 could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Android ID: A-30593765.
Android
CVE-2016-6711: Android Security Bulletin 2016-11-01
CVE: CVE-2016-6711
Severity: HIGH
Affected AOSP versions: 4
vendor_android·2016-11-01·CVSS 5.5
CVE-2016-6711 [MEDIUM] CVE-2016-6711: Android Security Bulletin 2016-11-01
CVE: CVE-2016-6711
Severity: HIGH
Affected AOSP versions: 4
Android Security Bulletin 2016-11-01
CVE: CVE-2016-6711
Severity: HIGH
Affected AOSP versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1
References: A-30593765
Debian
CVE-2016-6711: libvpx - A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x...
vendor_debian·2016·CVSS 5.5
CVE-2016-6711 [MEDIUM] CVE-2016-6711: libvpx - A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x...
A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-01 could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Android ID: A-30593765.
Scope: local
bookworm: resolved (fixed in 1.6.1-1)
bullseye: resolved (fixed in 1.6.1-1)
forky: resolved (fixed in 1.6.1-1)
sid: resolved (fixed in 1.6.1-1)
trixie: resolved (fixed in 1.6.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/94137https://android.googlesource.com/platform/external/libvpx/+/063be1485e0099bc81ace3a08b0ec9186dcad693https://source.android.com/security/bulletin/2016-11-01.htmlhttp://www.securityfocus.com/bid/94137https://android.googlesource.com/platform/external/libvpx/+/063be1485e0099bc81ace3a08b0ec9186dcad693https://source.android.com/security/bulletin/2016-11-01.html
2016-12-13
Published