Vulnerability Description
The Parcel::appendFrom function in libs/binder/Parcel.cpp in Binder in Android before 5.1.1 LMY48M does not consider parcel boundaries during identification of binder objects in an append operation, which allows attackers to obtain a different application's privileges via a crafted application, aka internal bug 17312693.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Android | <= 5.1 |
Related Weaknesses (CWE)
References
- https://android.googlesource.com/platform/frameworks/native/+/e68cbc3e9e66df4231Vendor Advisory
- https://groups.google.com/forum/message/raw?msg=android-security-updates/1M7qbSvVendor Advisory
- https://android.googlesource.com/platform/frameworks/native/+/e68cbc3e9e66df4231Vendor Advisory
- https://groups.google.com/forum/message/raw?msg=android-security-updates/1M7qbSvVendor Advisory
FAQ
What is CVE-2015-3845?
CVE-2015-3845 is a vulnerability with a CVSS score of 6.8 (MEDIUM). The Parcel::appendFrom function in libs/binder/Parcel.cpp in Binder in Android before 5.1.1 LMY48M does not consider parcel boundaries during identification of binder objects in an append operation, w...
How severe is CVE-2015-3845?
CVE-2015-3845 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-3845?
Check the references section above for vendor advisories and patch information. Affected products include: Google Android.