Description
Race condition in Download Manager in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows attackers to bypass private-storage file-access restrictions via a crafted application that changes a symlink target, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26211054.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-0859 | Race condition in Download Manager in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows attackers to bypass private-storage file-access restrictions via a crafted application that changes a symlink target, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26211054. |
References
History
No history.
Status: PUBLISHED
Assigner: google_android
Published:
Updated: 2024-08-05T22:30:05.034Z
Reserved: 2015-12-16T00:00:00.000Z
Link: CVE-2016-0848
No data.
Status : Deferred
Published: 2016-04-18T00:59:12.370
Modified: 2025-04-12T10:46:40.837
Link: CVE-2016-0848
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD