First published: Mon Nov 07 2016(Updated: )
An information disclosure vulnerability in libstagefright in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Android ID: A-29422020.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | >=4.0<4.4.4 | |
Google Android | >=5.0<5.0.2 | |
Google Android | >=5.1<5.1.1 | |
Google Android | >=6.0<=6.0.1 | |
Google Android | =7.0 | |
https://android.googlesource.com/platform/frameworks/av/+/0f177948ae2640bfe4d70f8e4248e106406b3b0a
https://android.googlesource.com/platform/frameworks/av/+/2c75e1c3b98e4e94f50c63e2b7694be5f948477c
https://android.googlesource.com/platform/frameworks/av/+/640b04121d7cd2cac90e2f7c82b97fce05f074a5
https://android.googlesource.com/platform/frameworks/av/+/7c88b498fda1c2b608a9dd73960a2fd4d7b7e3f7
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6720 is classified as a medium severity vulnerability due to its potential for information disclosure.
To mitigate CVE-2016-6720, users should update their Android devices to the latest version that is not affected by this vulnerability.
CVE-2016-6720 affects Android versions prior to 4.4.4, 5.0.2, 5.1.1, and 6.0.1, as well as Android 7.0 before November 1, 2016.
Yes, a local malicious application can exploit CVE-2016-6720 to access data outside of its designated permission levels.
CVE-2016-6720 is not classified as critical, but it poses a risk of information disclosure that should be addressed promptly.