{"id":"UBUNTU-CVE-2016-6702","details":"A remote code execution vulnerability in libjpeg in Android 4.x before 4.4.4, 5.0.x before 5.0.2, and 5.1.x before 5.1.1 could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses libjpeg. Android ID: A-30259087.","modified":"2026-04-22T10:54:51.282691Z","published":"2016-11-25T16:59:00Z","upstream":["CVE-2016-6702"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2016-6702"},{"type":"REPORT","url":"https://source.android.com/security/bulletin/2016-11-01.html"},{"type":"REPORT","url":"https://github.com/android-security/android_external_jpeg/commit/19a6799932f7468f24c972f9acfc314ebbfc9ab2"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2016-6702"}],"affected":[{"package":{"name":"oxide-qt","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/oxide-qt@1.21.5-0ubuntu0.16.04.1?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.9.5-0ubuntu1","1.10.3-0ubuntu0.15.10.1","1.10.3-0ubuntu0.15.10.2","1.11.3-0ubuntu3","1.11.4-0ubuntu1","1.11.5-0ubuntu1","1.12.5-0ubuntu1","1.12.6-0ubuntu1","1.12.7-0ubuntu1","1.13.6-0ubuntu1","1.14.7-0ubuntu1","1.14.9-0ubuntu0.16.04.1","1.15.7-0ubuntu0.16.04.1","1.15.8-0ubuntu0.16.04.1","1.16.5-0ubuntu0.16.04.1","1.17.7-0ubuntu0.16.04.1","1.17.9-0ubuntu0.16.04.1","1.18.3-0ubuntu0.16.04.1","1.18.5-0ubuntu0.16.04.1","1.19.4-0ubuntu0.16.04.1","1.20.4-0ubuntu0.16.04.1","1.21.5-0ubuntu0.16.04.1"],"ecosystem_specific":{"binaries":[{"binary_name":"liboxideqt-qmlplugin","binary_version":"1.21.5-0ubuntu0.16.04.1"},{"binary_name":"liboxideqtcore0","binary_version":"1.21.5-0ubuntu0.16.04.1"},{"binary_name":"liboxideqtquick0","binary_version":"1.21.5-0ubuntu0.16.04.1"},{"binary_name":"oxideqt-codecs","binary_version":"1.21.5-0ubuntu0.16.04.1"},{"binary_name":"oxideqt-codecs-extra","binary_version":"1.21.5-0ubuntu0.16.04.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2016/UBUNTU-CVE-2016-6702.json"}},{"package":{"name":"android","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/android@20160330-0939-0ubuntu1?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["20150818-1500-0ubuntu2","20150818-1500-0ubuntu3","20160307-0742-0ubuntu3","20160330-0939-0ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"android","binary_version":"20160330-0939-0ubuntu1"},{"binary_name":"android-copyright","binary_version":"20160330-0939-0ubuntu1"},{"binary_name":"android-emulator","binary_version":"20160330-0939-0ubuntu1"},{"binary_name":"ubuntu-emulator-images","binary_version":"20160330-0939-0ubuntu1"},{"binary_name":"ubuntu-emulator-runtime","binary_version":"20160330-0939-0ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2016/UBUNTU-CVE-2016-6702.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}