Security Advisory

CVE-2014-7911

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2014-12-15 17:27:00
Last updated 2024-08-06 13:03:27
Assigner Chrome
CVSS score not scored
State PUBLISHED

Description

luni/src/main/java/java/io/ObjectInputStream.java in the java.io.ObjectInputStream implementation in Android before 5.0.0 does not verify that deserialization will result in an object that met the requirements for serialization, which allows attackers to execute arbitrary code via a crafted finalize method for a serialized object in an ArrayMap Parcel within an intent sent to system_service, as demonstrated by the finalize method of android.os.BinderProxy, aka Bug 15874291.