Description
An information disclosure vulnerability in Conscrypt and BoringSSL in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable a man-in-the-middle attacker to gain access to sensitive information if a non-standard cipher suite is used by an application. This issue is rated as High because it could be used to access data without permission. Android ID: A-31081987.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-7612 | An information disclosure vulnerability in Conscrypt and BoringSSL in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable a man-in-the-middle attacker to gain access to sensitive information if a non-standard cipher suite is used by an application. This issue is rated as High because it could be used to access data without permission. Android ID: A-31081987. |
References
History
No history.
Status: PUBLISHED
Assigner: google_android
Published:
Updated: 2024-08-06T01:36:29.567Z
Reserved: 2016-08-11T00:00:00.000Z
Link: CVE-2016-6709
No data.
Status : Modified
Published: 2016-11-25T16:59:15.220
Modified: 2026-05-06T22:30:45.220
Link: CVE-2016-6709
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD