The updateMessageStatus function in Android 5.1.1 and earlier allows local users to cause a denial of service (NULL pointer exception and process crash).
References
Link | Resource |
---|---|
https://huntcve.github.io/2017/02/13/cveupdate/ | Broken Link |
http://blog.trendmicro.com/trendlabs-security-intelligence/two-new-android-bugs-mess-up-messaging-may-lead-to-multiple-send-charges/ | Technical Description Third Party Advisory |
http://blog.trendmicro.com/trendlabs-security-intelligence/os-x-zero-days-on-the-rise-a-2015-midyear-review-on-advanced-attack-surfaces/ | Technical Description Third Party Advisory |
http://www.securityfocus.com/bid/100158 | Third Party Advisory VDB Entry |
Configurations
Information
Published : 2017-08-07 10:29
Updated : 2017-08-09 12:45
NVD link : CVE-2015-3839
Mitre link : CVE-2015-3839
JSON object : View
CWE
CWE-476
NULL Pointer Dereference
Products Affected
- android