Vulnerabilities > CVE-2016-5348 - Resource Management Errors vulnerability in Google Android

047910
CVSS 5.9 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
high complexity
google
CWE-399
exploit available

Summary

The GPS component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows man-in-the-middle attackers to cause a denial of service (memory consumption, and device hang or reboot) via a large xtra.bin or xtra2.bin file on a spoofed Qualcomm gpsonextra.net or izatcloud.net host, aka internal bug 29555864.

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionAndroid - 'gpsOneXtra' Data Files Denial of Service. CVE-2016-5348. Dos exploit for Android platform
fileexploits/android/dos/40502.txt
idEDB-ID:40502
last seen2016-10-11
modified2016-10-11
platformandroid
port
published2016-10-11
reporterNightwatch Cybersecurity Research
sourcehttps://www.exploit-db.com/download/40502/
titleAndroid - 'gpsOneXtra' Data Files Denial of Service
typedos

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/139033/androidgps-dos.txt
idPACKETSTORM:139033
last seen2016-12-05
published2016-10-10
reporterYakov Shafranovich
sourcehttps://packetstormsecurity.com/files/139033/Android-Qualcomm-GPS-GNSS-Man-In-The-Middle.html
titleAndroid Qualcomm GPS/GNSS Man-In-The-Middle