Android AudioSource. cpp Information Leakage Vulnerability (CVE-2016-2499)
Android AudioSource. cpp Information Leakage Vulnerability (CVE-2016-2499)
Release date:
Updated on:
Affected Systems:
Android 6.x <2016-06-01
Android 5.1.x <5.1.1
Android 5.0.x <5.0.2
Android 4.x <4.4.4
Description:
CVE (CAN) ID: CVE-2016-2499
Android is a mobile phone operating system based on the Linux open kernel.
Android 4.x <4.4.4, 5.0.x <5.0.2, 5.1.x <5.1.1, 6.x <2016-06-01, mediaserver/libstagefright/AudioSource. cpp does not initialize some data. Attackers can exploit the constructed application to obtain sensitive information.
<* Source: Processing ing Gong
*>
Suggestion:
Vendor patch:
Android
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://source.android.com/security/bulletin/2016-06-01.html
Https://android.googlesource.com/platform/frameworks/av/+/dd3546765710ce8dd49eb23901d90345dec8282f
This article permanently updates the link address: