CVE-2016-0818
Publication date 12 March 2016
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
The caching functionality in the TrustManagerImpl class in TrustManagerImpl.java in Conscrypt in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 mishandles the distinction between an intermediate CA and a trusted root CA, which allows man-in-the-middle attackers to spoof servers by leveraging access to an intermediate CA to issue a certificate, aka internal bug 26232830.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| android | 18.04 LTS bionic | Not in release |
| 16.04 LTS xenial |
Fixed 20160307-0742-0ubuntu3
|
|
| 14.04 LTS trusty | Not in release | |
Patch details
| Package | Patch details |
|---|---|
| android |
Severity score breakdown
CVSS version: CVSS v3.0
Base score
5.9 · Medium
Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N