CVE-2016-2036
5.5
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 1.8 / Impact: 3.6
Source: NVD
Description
The getURL function in drivers/secfilter/urlparser.c in secfilter in the Samsung kernel for Android on SM-N9005 build N9005XXUGBOB6 (Note 3) and SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to trigger a NULL pointer dereference via a "GET HTTP/1.1" request, aka SVE-2016-5036.
Affected (2)
Products: Samsung: Galaxy S6 Firmware, Galaxy Note 3 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version g920fxxu2coh2 |
| Running on/with | Platform Versions |
|---|---|
Samsung Galaxy S6 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version n9005xxugbob6 |
| Running on/with | Platform Versions |
|---|---|
Samsung Galaxy Note 3 | All versions |
Related CWEs
References (2)
Source: cve@mitre.org
ExploitTechnical DescriptionThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitTechnical DescriptionThird Party Advisory
Timeline
No history available yet.