CVE-2016-0808
Last modified
CVE-2016-0808 is a vulnerability of currently unknown severity. Integer overflow in the getCoverageFormat12 function in CmapCoverage.cpp in the Minikin library in Android 5.x before 5.1.1 LMY49G and 6.x before 2016-02-01 allows attackers to cause a denial of service (continuous rebooting) via an application that triggers loading of a crafted TTF font, aka internal bug 25645298.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
Integer overflow in the getCoverageFormat12 function in CmapCoverage.cpp in the Minikin library in Android 5.x before 5.1.1 LMY49G and 6.x before 2016-02-01 allows attackers to cause a denial of service (continuous rebooting) via an application that triggers loading of a crafted TTF font, aka internal bug 25645298.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | 5.0 | |
| Android | 5.0.1 | |
| Android | 5.0.2 | |
| Android | 5.1 | |
| Android | 5.1.0 | |
| Android | 5.1.1 | |
| Android | 6.0 | |
| Android | 6.0.1 |
References
- http://source.android.com/security/bulletin/2016-02-01.htmlVendor Advisory
- http://source.android.com/security/bulletin/2016-02-01.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-0808?
How severe is CVE-2016-0808?
How do I fix CVE-2016-0808?
Are you affected by CVE-2016-0808?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
