First published: Thu Mar 29 2018(Updated: )
The ESRI ArcGis Runtime SDK before 10.2.6-2 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-controlled pointer to a native function.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Esri Arcgisruntime Sdk | <10.2.6-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2002 is rated as a high severity vulnerability due to the potential for arbitrary code execution.
To fix CVE-2015-2002, update to a version of the ESRI ArcGis Runtime SDK for Android later than 10.2.6-2.
CVE-2015-2002 affects the ESRI ArcGis Runtime SDK for Android before version 10.2.6-2.
CVE-2015-2002 can be exploited by attackers to execute arbitrary code through an improperly handled pointer in a Serializable class.
CVE-2015-2002 is not a persistent vulnerability as it affects specific SDK versions prior to 10.2.6-2.