Candidate: CVE-2015-6622 PublicDate: 2015-12-08 23:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-6622 http://source.android.com/security/bulletin/2015-12-01.html Description: The Native Frameworks Library in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 23905002. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Qidan He and Marco Grassi Assigned-to: CVSS: Patches_android: upstream: https://android.googlesource.com/platform/frameworks/native/+/5d17838adef13062717322e79d4db0b9bb6b2395%5E%21/ upstream_android: released (6.0 2015-12-01) precise_android: DNE trusty_android: ignored (code not compiled) trusty/esm_android: DNE (trusty was ignored [code not compiled]) vivid_android: ignored (code not compiled) vivid/stable-phone-overlay_android: ignored (code not compiled) vivid/ubuntu-core_android: DNE wily_android: ignored (code not compiled) devel_android: ignored (code not compiled)