CVE-2015-3863
Publication date 1 October 2015
Last updated 24 July 2024
Ubuntu priority
Description
Multiple integer overflows in the Blob class in keystore/keystore.cpp in Keystore in Android before 5.1.1 LMY48M allow attackers to execute arbitrary code and read arbitrary Keystore keys via an application that uses a crafted blob in an insert operation, aka internal bug 22802399.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| android | 18.04 LTS bionic | Not in release |
| 16.04 LTS xenial | Ignored end of standard support | |
| 14.04 LTS trusty | Not in release | |
References
Other references
- https://android.googlesource.com/platform/system/security/+/bb9f4392c2f1b11be3acdc1737828274ff1ec55b
- https://groups.google.com/forum/#!topic/android-security-updates/iv1BF0f0XY4
- https://android.googlesource.com/platform/system/security/+/0d5935262dbbcaf2cf6145529ffd71a728ef4609%5E!/#F0
- https://www.cve.org/CVERecord?id=CVE-2015-3863