On Samsung Galaxy S4 through S7 devices, absence of permissions on the BroadcastReceiver responsible for handling the com.[Samsung].android.intent.action.SET_WIFI intent leads to unsolicited configuration messages being handled by wifi-service.jar within the Android Framework, a subset of SVE-2016-6542.
Weaknesses in this category are related to improper assignment or handling of permissions.
Link | Tags |
---|---|
http://security.samsungmobile.com/smrupdate.html#SMR-AUG-2016 | vendor advisory |
http://www.securityfocus.com/bid/94081 | vdb entry third party advisory |