CVE-2016-0818
Last modified
CVE-2016-0818 is a vulnerability of currently unknown severity. The caching functionality in the TrustManagerImpl class in TrustManagerImpl.java in Conscrypt in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 mishandles the distinction between an intermediate CA and a trusted root CA, which allows man-in-the-middle attackers to spoof servers by leveraging access to an intermediate CA to issue a certificate, aka internal bug 26232830.. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
The caching functionality in the TrustManagerImpl class in TrustManagerImpl.java in Conscrypt in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 mishandles the distinction between an intermediate CA and a trusted root CA, which allows man-in-the-middle attackers to spoof servers by leveraging access to an intermediate CA to issue a certificate, aka internal bug 26232830.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | 4.0 | |
| Android | 4.0.1 | |
| Android | 4.0.2 | |
| Android | 4.0.3 | |
| Android | 4.0.4 | |
| Android | 4.1 | |
| Android | 4.1.2 | |
| Android | 4.2 | |
| Android | 4.2.1 | |
| Android | 4.2.2 | |
| Android | 4.3 | |
| Android | 4.3.1 | |
| Android | 4.4 | |
| Android | 4.4.1 | |
| Android | 4.4.2 | |
| Android | 4.4.3 | |
| Android | 5.0 | |
| Android | 5.0.1 | |
| Android | 5.0.2 | |
| Android | 5.1 | |
| Android | 5.1.0 | |
| Android | 5.1.1 | |
| Android | 6.0 | |
| Android | 6.0.1 |
References
- http://source.android.com/security/bulletin/2016-03-01.htmlVendor Advisory
- http://source.android.com/security/bulletin/2016-03-01.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-0818?
How severe is CVE-2016-0818?
How do I fix CVE-2016-0818?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-0810media/libmedia/SoundPool.cpp in mediaserver in Android 4.x b…
- CVE-2016-0811Integer overflow in the BnCrypto::onTransact function in med…
- CVE-2016-0812The interceptKeyBeforeDispatching function in policy/src/com…
- CVE-2016-0813packages/SystemUI/src/com/android/systemui/recents/Alternate…
- CVE-2016-0815The MPEG4Source::fragmentedRead function in MPEG4Extractor.c…
- CVE-2016-0816mediaserver in Android 6.x before 2016-03-01 allows remote a…
- CVE-2016-0819The Qualcomm performance component in Android 4.x before 4.4…
- CVE-2016-0820The MediaTek Wi-Fi kernel driver in Android 6.0.1 before 201…
- CVE-2016-0821The LIST_POISON feature in include/linux/poison.h in the Lin…5.5
- CVE-2016-0822The MediaTek connectivity kernel driver in Android 6.0.1 bef…
- CVE-2016-0823The pagemap_open function in fs/proc/task_mmu.c in the Linux…
- CVE-2016-0824libmpeg2 in libstagefright in Android 6.x before 2016-03-01 …
Are you affected by CVE-2016-0818?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
