CVE-2016-6702: High severity Google Android vulnerability
A remote code execution vulnerability in libjpeg in Android 4.x before 4.4.4, 5.0.x before 5.0.2, and 5.1.x before 5.1.1 could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses libjpeg. Android ID: A-30259087.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6702?
CVE-2016-6702 is rated as High due to the potential for remote code execution in unprivileged processes.
How can I mitigate CVE-2016-6702?
To mitigate CVE-2016-6702, update your Android device to a version later than 5.0.2 or 5.1.1.
What versions of Android are affected by CVE-2016-6702?
CVE-2016-6702 affects Android versions 4.x before 4.4.4, 5.0.x before 5.0.2, and 5.1.x before 5.1.1.
What type of vulnerability is CVE-2016-6702?
CVE-2016-6702 is a remote code execution vulnerability in the libjpeg library.
Who is at risk from CVE-2016-6702?
Users of the affected versions of Android are at risk of exploitation through specially crafted files.