First published: Mon Nov 07 2016(Updated: )
A remote code execution vulnerability in libjpeg in Android 4.x before 4.4.4, 5.0.x before 5.0.2, and 5.1.x before 5.1.1 could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses libjpeg. Android ID: A-30259087.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Android | =4.0 | |
Android | =4.0.1 | |
Android | =4.0.2 | |
Android | =4.0.3 | |
Android | =4.0.4 | |
Android | =4.1 | |
Android | =4.1.2 | |
Android | =4.2 | |
Android | =4.2.1 | |
Android | =4.2.2 | |
Android | =4.3 | |
Android | =4.3.1 | |
Android | =4.4 | |
Android | =4.4.1 | |
Android | =4.4.2 | |
Android | =4.4.3 | |
Android | =5.0 | |
Android | =5.0.1 | |
Android | =5.1 | |
Android | =5.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6702 is rated as High due to the potential for remote code execution in unprivileged processes.
To mitigate CVE-2016-6702, update your Android device to a version later than 5.0.2 or 5.1.1.
CVE-2016-6702 affects Android versions 4.x before 4.4.4, 5.0.x before 5.0.2, and 5.1.x before 5.1.1.
CVE-2016-6702 is a remote code execution vulnerability in the libjpeg library.
Users of the affected versions of Android are at risk of exploitation through specially crafted files.