CVE-2015-6783
The FindStartOffsetOfFileInZipFile function in crazy_linker_zip.cpp in crazy_linker (aka Crazy Linker) in Android 5.x and 6.x, as used in Google Chrome before 47.0.2526.73, improperly searches for an EOCD record, which allows attackers to bypass a…
Does this matter?
Lower severity and a low EPSS score (1.23%). Track it; it rarely justifies an emergency change on its own.
Description
The FindStartOffsetOfFileInZipFile function in crazy_linker_zip.cpp in crazy_linker (aka Crazy Linker) in Android 5.x and 6.x, as used in Google Chrome before 47.0.2526.73, improperly searches for an EOCD record, which allows attackers to bypass a signature-validation requirement via a crafted ZIP archive.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.23% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- google/android
- Source
- chrome-cve-admin@google.com
References
- http://googlechromereleases.blogspot.com/2015/12/stable-channel-update.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00016.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00017.html
- http://www.securityfocus.com/bid/78416
- http://www.securitytracker.com/id/1034298
- https://chromium.googlesource.com/chromium/src.git/+/d9e316238aee59acf665d80b544cf4e1edfd3349
- https://code.google.com/p/chromium/issues/detail?id=537205
- https://security.gentoo.org/glsa/201603-09
- http://googlechromereleases.blogspot.com/2015/12/stable-channel-update.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00016.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00017.html
- http://www.securityfocus.com/bid/78416
- http://www.securitytracker.com/id/1034298
- https://chromium.googlesource.com/chromium/src.git/+/d9e316238aee59acf665d80b544cf4e1edfd3349
- https://code.google.com/p/chromium/issues/detail?id=537205
- https://security.gentoo.org/glsa/201603-09
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.