Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-3845

Опубликовано: 01 окт. 2015
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.8

Описание

The Parcel::appendFrom function in libs/binder/Parcel.cpp in Binder in Android before 5.1.1 LMY48M does not consider parcel boundaries during identification of binder objects in an append operation, which allows attackers to obtain a different application's privileges via a crafted application, aka internal bug 17312693.

РелизСтатусПримечание
artful

DNE

bionic

DNE

devel

DNE

esm-apps-legacy/xenial

ignored

abandoned
esm-apps/xenial

ignored

end of ESM support, was ignored [abandoned]
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was ignored [abandoned]]
precise

DNE

precise/esm

DNE

trusty

ignored

end of standard support
trusty/esm

DNE

trusty was ignored [abandoned]

Показывать по

EPSS

Процентиль: 47%
0.00607
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

nvd
почти 11 лет назад

The Parcel::appendFrom function in libs/binder/Parcel.cpp in Binder in Android before 5.1.1 LMY48M does not consider parcel boundaries during identification of binder objects in an append operation, which allows attackers to obtain a different application's privileges via a crafted application, aka internal bug 17312693.

github
больше 4 лет назад

The Parcel::appendFrom function in libs/binder/Parcel.cpp in Binder in Android before 5.1.1 LMY48M does not consider parcel boundaries during identification of binder objects in an append operation, which allows attackers to obtain a different application's privileges via a crafted application, aka internal bug 17312693.

fstec
почти 11 лет назад

Уязвимость операционной системы Android, позволяющая нарушителю получить привилегии различных приложений

EPSS

Процентиль: 47%
0.00607
Низкий

6.8 Medium

CVSS2