server/TetherController.cpp in the tethering controller in netd, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not properly validate upstream interface names, which allows attackers to bypass intended access restrictions via a crafted application.
References
Configurations
Information
Published : 2016-05-09 03:59
Updated : 2016-05-16 06:56
NVD link : CVE-2016-2060
Mitre link : CVE-2016-2060
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
- android