CVE-2016-6701
Published on: 11/25/2016 12:00:00 AM UTC
Last Modified on: 03/23/2021 11:27:10 PM UTC
Certain versions of Android from Google contain the following vulnerability:
A remote code execution vulnerability in libskia in Android 7.0 before 2016-11-01 could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as High due to the possibility of remote code execution within the context of the gallery process. Android ID: A-30190637.
- CVE-2016-6701 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
Google Inc. - Android version Android-7.0
CVSS3 Score: 7.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
|
---|---|---|---|---|
LOCAL | LOW | NONE | REQUIRED | |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
|
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 6.8 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Google Android Skia CVE-2016-6701 Memory Corruption Vulnerability | Third Party Advisory VDB Entry cve.report (archive) text/html |
![]() |
Android Security Bulletin—November 2016 | Android Open Source Project | Vendor Advisory source.android.com text/html |
![]() |
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Android | All | All | All | All |
- cpe:2.3:o:google:android:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE