SB2017011220 - Multiple vulnerabilities in Samsung Mobile



SB2017011220 - Multiple vulnerabilities in Samsung Mobile

Published: January 12, 2017 Updated: August 9, 2020

Security Bulletin ID SB2017011220
Severity
High
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 50% Medium 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Out-of-bounds read (CVE-ID: CVE-2017-5538)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The kbase_dispatch function in arm/t7xx/r5p0/mali_kbase_core_linux.c in the GPU driver on Samsung devices with M(6.0) and N(7.0) software and Exynos AP chipsets allows attackers to have unspecified impact via unknown vectors, which trigger an out-of-bounds read, aka SVE-2016-6362.


2) Input validation error (CVE-ID: CVE-2017-5350)

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

Samsung Note devices with L(5.0/5.1), M(6.0), and N(7.0) software allow attackers to crash systemUI by leveraging incomplete exception handling. The Samsung ID is SVE-2016-7122.


Remediation

Install update from vendor's website.