Home / vulnerabilitiesPDF  

Android BnBluetoothGattServer / BnBluetoothGatServerCallback IPC Memory Corruption

Posted on 11 March 2016
Source : packetstormsecurity.org Link

 

The SEND_RESPONSE_TRANSACTION and SEND_NOTIFICATION_TRANSACTION IPC calls in BnBluetoothGattServer::onTransact are vulnerable to stack corruption which could allow an attacker to locally elevate privileges to the level of the bluetooth service.

 

TOP