service/jni/com_android_server_wifi_Gbk2Utf.cpp in the Qualcomm Wi-Fi gbk2utf module in Android before 2016-10-05 allows remote attackers to cause a denial of service (framework crash) or possibly have unspecified other impact via an access point that has a malformed SSID with GBK encoding, aka Qualcomm internal bug CR 978452.
The product does not properly encode or decode the data, resulting in unexpected values.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/93330 | third party advisory vdb entry |
http://source.android.com/security/bulletin/2016-10-01.html | vendor advisory |
https://source.codeaurora.org/quic/la//platform/frameworks/opt/net/wifi/commit/?id=343f123c396b2a97fc7cce396cd5d99365cb9131 | patch issue tracking |