HIGH
OpenSSLCipher.java in Conscrypt in Android 6.x before 2016-05-01 mishandles updates of the Additional Authenticated Data (AAD) array, which allows attackers to spoof message authentication via unspecified vectors, aka internal bug 27371173
Published May 9, 2016
7.0
HIGHCVSS 3.0
EPSS 0.39%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.