Description
Off-by-one error in sdcard/sdcard.c in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 28085658.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Google Security Research · textdosandroid
https://www.exploit-db.com/exploits/39921
References (4)
Core 4
Core References
Patch x_refsource_confirm
https://android.googlesource.com/platform/system/core/+/864e2e22fcd0cba3f5e67680ccabd0302dfda45d
Exploit, Third Party Advisory x_refsource_misc
http://packetstormsecurity.com/files/137404/Android-system-bin-sdcard-Stack-Buffer-Overflow.html
Exploit, Third Party Advisory exploit
x_refsource_exploit-db
https://www.exploit-db.com/exploits/39921/
Vendor Advisory x_refsource_confirm
http://source.android.com/security/bulletin/2016-06-01.html
Scores
CVSS v3
7.8
EPSS
0.0107
EPSS Percentile
77.8%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-264
Status
published
Products (22)
google/android
4.0
google/android
4.0.1
google/android
4.0.2
google/android
4.0.3
google/android
4.0.4
google/android
4.1
google/android
4.1.2
google/android
4.2
google/android
4.2.1
google/android
4.2.2
... and 12 more
Published
Jun 13, 2016
Tracked Since
Feb 18, 2026