Stack-based buffer overflow in libsysutils in Android 2.2.x through 2.2.2 and 2.3.x through 2.3.6 allows user-assisted remote attackers to execute arbitrary code via an application that calls the FrameworkListener::dispatchCommand method with the wrong number of arguments, as demonstrated by zergRush to trigger a use-after-free error.
2012-01-27T15:55:04.237
2025-04-11T00:51:21.963
Deferred
CVSSv2: 9.3 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | android | 2.2 | Yes | |
Operating System | android | 2.2 | Yes | |
Operating System | android | 2.2.1 | Yes | |
Operating System | android | 2.2.2 | Yes | |
Operating System | android | 2.3 | Yes | |
Operating System | android | 2.3 | Yes | |
Operating System | android | 2.3.1 | Yes | |
Operating System | android | 2.3.2 | Yes | |
Operating System | android | 2.3.3 | Yes | |
Operating System | android | 2.3.4 | Yes | |
Operating System | android | 2.3.5 | Yes | |
Operating System | android | 2.3.6 | Yes |