ZeroHour

CVE-2016-7990

CVSS 3.0
9.8 critical
EPSS
2%p80
Published
()
Modified
Description

On Samsung Galaxy S4 through S7 devices, an integer overflow condition exists within libomacp.so when parsing OMACP messages (within WAP Push SMS messages) leading to a heap corruption that can result in Denial of Service and potentially remote code execution, a subset of SVE-2016-6542.

Vendors
google
Products
android
Weakness
CWE-190, CWE-388
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.