First published: Wed Oct 18 2017(Updated: )
cmds/servicemanager/service_manager.c in Android before commit 7d42a3c31ba78a418f9bdde0e0ab951469f321b5 allows attackers to cause a denial of service (NULL pointer dereference, or out-of-bounds write) via vectors related to binder passed lengths.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | <=4.4.4 |
https://sourceforge.net/p/android-x86/frameworks_native/ci/652c485467598240ecbb3a60516ad1140eddfab1/
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3164 has a severity rating that indicates it can lead to denial of service due to NULL pointer dereference or out-of-bounds write issues.
To fix CVE-2014-3164, update your Android device to a version later than 4.4.4 that includes the security patch.
CVE-2014-3164 affects Android versions up to 4.4.4 before the security patch was applied.
CVE-2014-3164 is a vulnerability that can cause denial of service due to improper handling of binder passed lengths.
An attacker with local access to the affected Android device can exploit CVE-2014-3164 to cause a denial of service.