packages/SystemUI/src/com/android/systemui/power/PowerNotificationWarnings.java in Android 5.x allows attackers to bypass a DEVICE_POWER permission requirement via a broadcast intent with the PNW.stopSaver action, aka internal bug 20918350.
References
Link | Resource |
---|---|
https://android.googlesource.com/platform/frameworks/base/+/05e0705177d2078fa9f940ce6df723312cfab976 | Issue Tracking Patch |
http://seclists.org/fulldisclosure/2016/May/71 | Mailing List Third Party Advisory |
http://seclists.org/fulldisclosure/2016/May/72 | Mailing List Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2016-08-07 14:59
Updated : 2016-08-10 10:42
NVD link : CVE-2015-3854
Mitre link : CVE-2015-3854
JSON object : View
CWE
CWE-284
Improper Access Control
Products Affected
- android