ID

VAR-201704-0254


CVE

CVE-2016-2567


TITLE

Samsung SM-N9005 and SM-G920F Samsung kernel for Android secfilter input validation vulnerability

Trust: 1.2

sources: CNVD: CNVD-2017-11327 // CNNVD: CNNVD-201704-751

DESCRIPTION

secfilter in the Samsung kernel for Android on SM-N9005 build N9005XXUGBOB6 (Note 3) and SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to bypass URL filtering by inserting an "exceptional URL" in the query string, as demonstrated by the http://should-have-been-filtered.example.com/?http://google.com URL. SamsungkernelforAndroidonSM-N9005 (Note3) and SM-G920F (GalaxyS6) are the cores of Samsung's Android system running on SM-N9005 (Note3) and SM-G920F (GalaxyS6) (smartphone). Secfilter is one of the URL parsing filter plugins. An input validation vulnerability exists in the secfilter of Samsungkernel for Android in SamsungSM-N9005 (Note3) and SM-G920F (GalaxyS6). Samsung kernel for Android on SM-N9005 (Note 3) and SM-G920F (Galaxy S6) are both Korean Samsung (Samsung) running on SM-N9005 (Note 3) and SM-G920F (Galaxy S6) (smart phones) The kernel of the Android system in. There is a security vulnerability in the secfilter of Samsung kernel for Android in Samsung SM-N9005(Note 3) and SM-G920F(Galaxy S6). The following products and versions are affected: Samsung SM-N9005 build N9005XXUGBOB6 (Note 3) version; SM-G920F build G920FXXU2COH2 (Galaxy S6) version

Trust: 2.25

sources: NVD: CVE-2016-2567 // JVNDB: JVNDB-2016-008457 // CNVD: CNVD-2017-11327 // VULHUB: VHN-91386

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2017-11327

AFFECTED PRODUCTS

vendor:samsungmodel:galaxy s6scope:eqversion:g920fxxu2coh2

Trust: 2.4

vendor:samsungmodel:galaxy note 3scope:eqversion:n9005xxugbob6

Trust: 1.6

vendor:samsungmodel:note 3scope:eqversion:n9005xxugbob6

Trust: 0.8

vendor:samsungmodel:galaxy s6 sm-g920f build g920fxxu2coh2scope: - version: -

Trust: 0.6

vendor:samsungmodel:note sm-n9005 build n9005xxugbob6scope:eqversion:3

Trust: 0.6

sources: CNVD: CNVD-2017-11327 // JVNDB: JVNDB-2016-008457 // CNNVD: CNNVD-201704-751 // NVD: CVE-2016-2567

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2016-2567
value: LOW

Trust: 1.0

NVD: CVE-2016-2567
value: LOW

Trust: 0.8

CNVD: CNVD-2017-11327
value: LOW

Trust: 0.6

CNNVD: CNNVD-201704-751
value: LOW

Trust: 0.6

VULHUB: VHN-91386
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2016-2567
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:P/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2017-11327
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:P/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-91386
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:P/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2016-2567
baseSeverity: LOW
baseScore: 3.3
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 1.8
impactScore: 1.4
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2017-11327 // VULHUB: VHN-91386 // JVNDB: JVNDB-2016-008457 // CNNVD: CNNVD-201704-751 // NVD: CVE-2016-2567

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-91386 // JVNDB: JVNDB-2016-008457 // NVD: CVE-2016-2567

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201704-751

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201704-751

CONFIGURATIONS

sources: JVNDB: JVNDB-2016-008457

PATCH

title:GALAXY Note 3 SM-N9005url:https://www.sammobile.com/devices/specs/SM-N9005/

Trust: 0.8

title:Galaxy S6 SM-G920Furl:https://www.sammobile.com/devices/specs/SM-G920F/

Trust: 0.8

sources: JVNDB: JVNDB-2016-008457

EXTERNAL IDS

db:NVDid:CVE-2016-2567

Trust: 3.1

db:JVNDBid:JVNDB-2016-008457

Trust: 0.8

db:CNVDid:CNVD-2017-11327

Trust: 0.6

db:CNNVDid:CNNVD-201704-751

Trust: 0.6

db:VULHUBid:VHN-91386

Trust: 0.1

sources: CNVD: CNVD-2017-11327 // VULHUB: VHN-91386 // JVNDB: JVNDB-2016-008457 // CNNVD: CNNVD-201704-751 // NVD: CVE-2016-2567

REFERENCES

url:https://github.com/ud2/advisories/tree/master/android/samsung/nocve-2016-0003

Trust: 3.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2016-2567

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2016-2567

Trust: 0.8

sources: CNVD: CNVD-2017-11327 // VULHUB: VHN-91386 // JVNDB: JVNDB-2016-008457 // CNNVD: CNNVD-201704-751 // NVD: CVE-2016-2567

SOURCES

db:CNVDid:CNVD-2017-11327
db:VULHUBid:VHN-91386
db:JVNDBid:JVNDB-2016-008457
db:CNNVDid:CNNVD-201704-751
db:NVDid:CVE-2016-2567

LAST UPDATE DATE

2024-11-23T21:54:45.151000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-11327date:2017-06-26T00:00:00
db:VULHUBid:VHN-91386date:2017-04-25T00:00:00
db:JVNDBid:JVNDB-2016-008457date:2017-05-19T00:00:00
db:CNNVDid:CNNVD-201704-751date:2017-06-07T00:00:00
db:NVDid:CVE-2016-2567date:2024-11-21T02:48:43.003

SOURCES RELEASE DATE

db:CNVDid:CNVD-2017-11327date:2017-06-26T00:00:00
db:VULHUBid:VHN-91386date:2017-04-13T00:00:00
db:JVNDBid:JVNDB-2016-008457date:2017-05-19T00:00:00
db:CNNVDid:CNNVD-201704-751date:2017-04-13T00:00:00
db:NVDid:CVE-2016-2567date:2017-04-13T16:59:01.143