UBUNTU-CVE-2016-2418

Source
https://ubuntu.com/security/CVE-2016-2418
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2016/UBUNTU-CVE-2016-2418.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2016-2418
Upstream
  • CVE-2016-2418
Published
2016-04-18T00:59:00Z
Modified
2025-10-24T04:45:38Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

media/libmedia/IOMX.cpp in mediaserver in Android 6.x before 2016-04-01 does not initialize certain metadata buffer pointers, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified protection mechanism, via unspecified vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26324358.

References

Affected packages

Ubuntu:16.04:LTS / android

Package

Name
android
Purl
pkg:deb/ubuntu/android@20160330-0939-0ubuntu1?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

Other
20150818-1500-0ubuntu2
20150818-1500-0ubuntu3
20160307-0742-0ubuntu3
20160330-0939-0ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "android",
            "binary_version": "20160330-0939-0ubuntu1"
        },
        {
            "binary_name": "android-copyright",
            "binary_version": "20160330-0939-0ubuntu1"
        },
        {
            "binary_name": "android-emulator",
            "binary_version": "20160330-0939-0ubuntu1"
        },
        {
            "binary_name": "ubuntu-emulator-images",
            "binary_version": "20160330-0939-0ubuntu1"
        },
        {
            "binary_name": "ubuntu-emulator-runtime",
            "binary_version": "20160330-0939-0ubuntu1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2016/UBUNTU-CVE-2016-2418.json"