CVE-2016-8405Sensitive Information Exposure in INC Android

Severity
4.7MEDIUMNVD
OSV5.5
EPSS
0.3%
top 43.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 12
Latest updateMay 17

Description

An information disclosure vulnerability in kernel components including the ION subsystem, Binder, USB driver and networking subsystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31651010.

CVSS vector

CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.0 | Impact: 3.6

Affected Packages6 packages

Debianlinux/linux_kernel< 4.9.6-1+3
Ubuntulinux/linux_kernel< 3.13.0-126.175
NVDlinux/linux_kernel3.10, 3.18+1
CVEListV5google_inc/androidKernel-3.10, Kernel-3.18+1

🔴Vulnerability Details

5
GHSA
GHSA-2xmh-6vrf-q89v: An information disclosure vulnerability in kernel components including the ION subsystem, Binder, USB driver and networking subsystem could enable a l2022-05-17
OSV
linux vulnerabilities2017-08-07
OSV
linux-hwe vulnerabilities2017-07-21
Kernel
fbdev: color map copying bounds checking2017-01-24
OSV
CVE-2016-8405: An information disclosure vulnerability in kernel components including the ION subsystem, Binder, USB driver and networking subsystem could enable a l2017-01-12

📋Vendor Advisories

6
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities2017-08-07
Ubuntu
Linux kernel vulnerabilities2017-08-07
Ubuntu
Linux kernel (HWE) vulnerabilities2017-07-21
Red Hat
kernel: Copying color maps to userspace vulnerable to heap-buffer overflow2017-01-25
Android
CVE-2016-8405: Android Security Bulletin 2016-12-01 CVE: CVE-2016-8405 Severity: MEDIUM References: A-31651010*2016-12-01

💬Community

1
Bugzilla
CVE-2016-8405 kernel: Copying color maps to userspace vulnerable to heap-buffer overflow2017-02-23