Vulnerabilities > CVE-2015-1474 - Numeric Errors vulnerability in Google Android

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
google
CWE-189
critical

Summary

Multiple integer overflows in the GraphicBuffer::unflatten function in platform/frameworks/native/libs/ui/GraphicBuffer.cpp in Android through 5.0 allow attackers to gain privileges or cause a denial of service (memory corruption) via vectors that trigger a large number of (1) file descriptors or (2) integer values.

Common Weakness Enumeration (CWE)

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/130778/androidunflatten-overflow.txt
idPACKETSTORM:130778
last seen2016-12-05
published2015-03-12
reporterGuang Gong
sourcehttps://packetstormsecurity.com/files/130778/Google-Android-Integer-Oveflow-Heap-Corruption.html
titleGoogle Android Integer Oveflow / Heap Corruption