CVE-2014-9871: Buffer Overflow
Multiple buffer overflows in drivers/media/platform/msm/camerav2/isp/msmisputil.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices allow attackers to gain privileges via a crafted application, aka Android internal bug 28749803 and Qualcomm internal bug CR514717.
Affected Software
Remediation
Event History
Frequently Asked Questions
Which devices are identified as affected?
The affected devices identified are Nexus 5 and Nexus 7 (2013) devices running Android versions before 2016-08-05.
What does an attacker need to exploit this issue?
An attacker needs to get a crafted application executed on the device. The CVSS vector indicates local access, no privileges required, and user interaction is required.
What is the impact of successful exploitation?
Successful exploitation can allow an attacker to gain privileges. The vulnerability is rated critical and can affect confidentiality, integrity, and availability.
Is a fix available?
Yes. A patch is available; the referenced Android security bulletin is dated 2016-08-01.