Android IOMXNodeInstance::enableNativeBuffers Unchecked Index
Posted by deepcore on December 4, 2016 – 6:25 am
The code in IOMXNodeInstance.cpp that handles enableNativeBuffers uses port_index without validation, leading to writing the dword value 0 or 1 at an attacker controlled offset from the IOMXNodeInstance structure.
Post a reply
You must be logged in to post a comment.