server/TetherController.cpp in the tethering controller in netd, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not properly validate upstream interface names, which allows attackers to bypass intended access restrictions via a crafted application.
References
Configurations
History
No history.
Information
Published : 2016-05-09 10:59
Updated : 2016-05-16 13:56
NVD link : CVE-2016-2060
Mitre link : CVE-2016-2060
CVE.ORG link : CVE-2016-2060
JSON object : View
Products Affected
- android
CWE
CWE-264
Permissions, Privileges, and Access Controls