CVE-2016-0831
Publication date 12 March 2016
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
The getDeviceIdForPhone function in internal/telephony/PhoneSubInfoController.java in Telephony in Android 5.x before 5.1.1 LMY49H and 6.x before 2016-03-01 does not check for the READ_PHONE_STATE permission, which allows attackers to obtain sensitive information via a crafted application, aka internal bug 25778215.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| android | 18.04 LTS bionic | Not in release |
| 16.04 LTS xenial |
Fixed 20160307-0742-0ubuntu3
|
|
| 14.04 LTS trusty | Not in release | |
Patch details
| Package | Patch details |
|---|---|
| android |
Severity score breakdown
CVSS version: CVSS v3.0
Base score
5.5 · Medium
Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N