CVE-2016-6691
critical
CVSS v3
9.8
CVSS v2
7.5
VIR risk
9.8
Description
service/jni/com_android_server_wifi_Gbk2Utf.cpp in the Qualcomm Wi-Fi gbk2utf module in Android before 2016-10-05 allows remote attackers to cause a denial of service (framework crash) or possibly have unspecified other impact via an access point that has a malformed SSID with GBK encoding, aka Qualcomm internal bug CR 978452.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: security@android.com — https://source.codeaurora.org/quic/la//platform/frameworks/opt/net/wifi/commit/?id=343f123c396b2a97fc7cce396cd5d99365cb9131
Vendor advisory: security@android.com — http://source.android.com/security/bulletin/2016-10-01.html
References
- http://source.android.com/security/bulletin/2016-10-01.html
- http://www.securityfocus.com/bid/93330
- https://source.codeaurora.org/quic/la//platform/frameworks/opt/net/wifi/commit/?id=343f123c396b2a97fc7cce396cd5d99365cb9131
- http://source.android.com/security/bulletin/2016-10-01.html
- http://www.securityfocus.com/bid/93330
- https://source.codeaurora.org/quic/la//platform/frameworks/opt/net/wifi/commit/?id=343f123c396b2a97fc7cce396cd5d99365cb9131
CWEs
CWE-172
Verify integrity in audit chain (admin only). AS-IS.