Stack-based buffer overflow in libsysutils in Android 2.2.x through 2.2.2 and 2.3.x through 2.3.6 allows user-assisted remote attackers to execute arbitrary code via an application that calls the FrameworkListener::dispatchCommand method with the wrong number of arguments, as demonstrated by zergRush to trigger a use-after-free error.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published: 2012-01-27T15:00:00Z

Updated: 2024-09-17T04:20:10.355Z

Reserved: 2011-10-01T00:00:00Z

Link: CVE-2011-3874

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2012-01-27T15:55:04.237

Modified: 2023-11-07T02:08:42.083

Link: CVE-2011-3874

cve-icon Redhat

No data.