Android KeyStore Service CVE-2014-3100 Stack Buffer Overflow Vulnerability
BID:68152
Info
Android KeyStore Service CVE-2014-3100 Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 68152 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2014-3100 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 23 2014 12:00AM |
| Updated: | Jul 14 2014 05:28PM |
| Credit: | Roee Hay and Avi Dayan |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Android KeyStore Service CVE-2014-3100 Stack Buffer Overflow Vulnerability
Android is prone to a stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code in the context of the application and disclose sensitive information related to credentials.
Android 4.3 and prior are vulnerable.
Android is prone to a stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code in the context of the application and disclose sensitive information related to credentials.
Android 4.3 and prior are vulnerable.
Exploit / POC
Android KeyStore Service CVE-2014-3100 Stack Buffer Overflow Vulnerability
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
Solution / Fix
Android KeyStore Service CVE-2014-3100 Stack Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Android KeyStore Service CVE-2014-3100 Stack Buffer Overflow Vulnerability
References:
References:
- Android Homepage (Google)