dexdump in Android SDK before 2.3 does not properly perform structural verification, which allows user-assisted remote attackers to cause a denial of service (dexdump crash) and possibly execute arbitrary code via a malformed APK or dex file that calls a method using more arguments than the number of register that have been declared for that method.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2011-07-08T17:00:00
Updated: 2024-08-06T22:14:26.957Z
Reserved: 2011-02-14T00:00:00
Link: CVE-2011-1001
Vulnrichment
No data.
NVD
Status : Modified
Published: 2011-07-08T17:55:00.960
Modified: 2023-11-07T02:06:55.477
Link: CVE-2011-1001
Redhat
No data.