CVE-2012-6301: Input Validation
Published Dec 10, 2012
·Updated
The Browser application in Android 4.0.3 allows remote attackers to cause a denial of service (application crash) via a crafted market: URI in the SRC attribute of an IFRAME element.
Affected Software
1 affected component
Google Android=4.0.3
Event History
Dec 10, 2012
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-6301?
CVE-2012-6301 is classified as a moderate severity vulnerability due to its potential to cause application crashes.
2
How do I fix CVE-2012-6301?
The recommended fix for CVE-2012-6301 is to update the Android operating system to a version beyond 4.0.3 where this vulnerability has been addressed.
3
What type of attack is possible with CVE-2012-6301?
CVE-2012-6301 allows remote attackers to execute a denial of service attack by crafting a malicious market: URI.
4
Which version of Android is affected by CVE-2012-6301?
CVE-2012-6301 specifically affects Android version 4.0.3.
5
What is the impact of exploiting CVE-2012-6301?
Exploitation of CVE-2012-6301 can lead to the crash of the browser application, resulting in a denial of service.