SB2017011220 - Multiple vulnerabilities in Samsung Mobile
Published: January 12, 2017 Updated: August 9, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Out-of-bounds read (CVE-ID: CVE-2017-5538)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The kbase_dispatch function in arm/t7xx/r5p0/mali_kbase_core_linux.c in the GPU driver on Samsung devices with M(6.0) and N(7.0) software and Exynos AP chipsets allows attackers to have unspecified impact via unknown vectors, which trigger an out-of-bounds read, aka SVE-2016-6362.
2) Input validation error (CVE-ID: CVE-2017-5350)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
Samsung Note devices with L(5.0/5.1), M(6.0), and N(7.0) software allow attackers to crash systemUI by leveraging incomplete exception handling. The Samsung ID is SVE-2016-7122.
Remediation
Install update from vendor's website.