1
Candidate: CVE-2016-0831
4
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0831
5
http://source.android.com/security/bulletin/2016-03-01.html
7
The getDeviceIdForPhone function in
8
internal/telephony/PhoneSubInfoController.java in Telephony in Android 5.x
9
before 5.1.1 LMY49H and 6.x before 2016-03-01 does not check for the
10
READ_PHONE_STATE permission, which allows attackers to obtain sensitive
11
information via a crafted application, aka internal bug 25778215.
20
upstream: https://android.googlesource.com/platform/frameworks/opt/telephony/+/79eecef63f3ea99688333c19e22813f54d4a31b1
21
upstream_android: released
23
precise/esm_android: DNE
24
trusty_android: ignored (abandoned)
25
vivid/stable-phone-overlay_android: ignored (reached end-of-life)
26
vivid/ubuntu-core_android: DNE
27
wily_android: ignored (reached end-of-life)
28
xenial_android: released (20160307-0742-0ubuntu3)
29
yakkety_android: released (20160307-0742-0ubuntu3)
30
zesty_android: released (20160307-0742-0ubuntu3)