CVE-2014-9777: Buffer Overflow
The viddecsetmetabuffers function in drivers/video/msm/vidc/common/dec/vdec.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices does not validate the number of buffers, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28598501 and Qualcomm internal bug CR563654.
Affected Software
Event History
Frequently Asked Questions
Which devices are identified as affected?
The issue is identified on Nexus 5 and Nexus 7 (2013) devices running affected Android builds before 2016-07-05.
What does an attacker need to exploit this vulnerability?
An attacker needs to get a crafted application executed on the device. The supplied CVSS vector indicates local access, no privileges, and user interaction are required.
What is the likely impact of successful exploitation?
Successful exploitation can allow an attacker to gain privileges. The CVSS assessment rates confidentiality, integrity, and availability impact as high.