~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2016-2418

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2016-2418
2
 
PublicDate: 2016-04-17
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2418
5
 
 https://android.googlesource.com/platform/frameworks/av/+/8d87321b704cb3f88e8cae668937d001fd63d5e3
6
 
 http://source.android.com/security/bulletin/2016-04-02.html
7
 
Description:
8
 
 media/libmedia/IOMX.cpp in mediaserver in Android 6.x before 2016-04-01
9
 
 does not initialize certain metadata buffer pointers, which allows
10
 
 attackers to obtain sensitive information from process memory, and
11
 
 consequently bypass an unspecified protection mechanism, via unspecified
12
 
 vectors, as demonstrated by obtaining Signature or SignatureOrSystem
13
 
 access, aka internal bug 26324358.
14
 
Ubuntu-Description:
15
 
Notes:
16
 
Bugs:
17
 
Priority: medium
18
 
Discovered-by: Peter Pi
19
 
Assigned-to:
20
 
 
21
 
Patches_android:
22
 
upstream_android: released (6.x 2016-04-01)
23
 
precise_android: DNE
24
 
precise/esm_android: DNE
25
 
trusty_android: ignored (abandoned)
26
 
vivid/stable-phone-overlay_android: ignored (reached end-of-life)
27
 
vivid/ubuntu-core_android: DNE
28
 
wily_android: ignored (reached end-of-life)
29
 
xenial_android: ignored (abandoned)
30
 
yakkety_android: ignored (reached end-of-life)
31
 
zesty_android: ignored (reached end-of-life)
32
 
artful_android: DNE
33
 
bionic_android: DNE
34
 
devel_android: DNE