An elevation of privilege vulnerability in the recovery verifier could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-31914369.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://source.android.com/security/bulletin/2017-03-01 | |
http://www.securitytracker.com/id/1037968 | vdb entry |
http://www.securityfocus.com/bid/96716 | vdb entry |
https://source.android.com/security/bulletin/2017-03-01.html | vendor advisory |