oss-sec mailing list archives
CVE request - samsumg android phone TvoutService_C binder service DoS
From: Vinc3nt4H <pengdawei521 () 163 com>
Date: Thu, 5 May 2016 21:11:44 +0800 (CST)
Hi, Description of the potential vulnerability: When a app send a evil data to com. TvoutService_C service by service command (Android system command) , can cause to TvoutService_C service crash. Steps to reproduce the issue: 1 A PC connect S6 device; 2 Input command: adb shell; 3 Android Input command: service call TvoutService_C 22 i32 1090056453 i32 1428574234 i32 836766018 i32 779588542 Affected versions: KK(4.4), L(5.0/5.1), M(6.0) Fix: http://security.samsungmobile.com/smrupdate.html#SMR-FEB-2016 SVE-2016-5134: TvoutService_C service DoS We report this to samsung, samsung reply to us if we want to get CVE request it by ourself. Best regards, Vinc3nt4H of Alibaba Mobile Security Team
Current thread:
- CVE request - samsumg android phone TvoutService_C binder service DoS Vinc3nt4H (May 05)
- Re: CVE request - samsumg android phone TvoutService_C binder service DoS cve-assign (May 05)