Description
Unspecified vulnerability in libpng before 1.6.20, as used in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01, allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 23265085.
CVSS Metrics
- Vector
- CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Vector
- local
- Complexity
- low
- Privileges
- none
- User Action
- required
- Scope
- unchanged
- Confidentiality
- high
- Integrity
- high
- Availability
- high
- Weaknesses
- NVD-CWE-noinfo
Metadata
- Primary Vendor
- LIBPNG
- Published
- 7/11/2016
- Last Modified
- 4/12/2025
- Source
- NIST NVD
- Note: Verify all details with official vendor sources before applying patches.
Affected Products
libpng : libpnggoogle : androidgoogle : androidgoogle : androidgoogle : androidgoogle : androidgoogle : androidgoogle : androidgoogle : androidgoogle : androidgoogle : androidgoogle : androidgoogle : androidgoogle : androidgoogle : androidgoogle : androidgoogle : androidgoogle : androidgoogle : androidgoogle : androidgoogle : androidgoogle : androidgoogle : android
AI-Powered Remediation
Generate remediation guidance or a C-suite brief for this vulnerability.