First published: Thu Mar 29 2018(Updated: )
The ESRI ArcGis Runtime SDK before 10.2.6-2 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-controlled pointer to a native function.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Esri Arcgisruntime Sdk | <10.2.6-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.