Back to search
CVE-2016-5348
Published: Oct 10, 2016
Modified: Sep 17, 2024
PUBLISHED
Description
The GPS component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows man-in-the-middle attackers to cause a denial of service (memory consumption, and device hang or reboot) via a large xtra.bin or xtra2.bin file on a spoofed Qualcomm gpsonextra.net or izatcloud.net host, aka internal bug 29555864.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
93293
vdb-entry
x_refsource_BID
https://source.android.com/security/bulletin/2018-04-01
x_refsource_CONFIRM
http://source.android.com/security/bulletin/2016-10-01.html
x_refsource_CONFIRM
https://code.google.com/p/android/issues/detail?id=213747
x_refsource_CONFIRM
40502
exploit
x_refsource_EXPLOIT-DB
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now