First published: Mon Feb 16 2015(Updated: )
Multiple integer overflows in the GraphicBuffer::unflatten function in platform/frameworks/native/libs/ui/GraphicBuffer.cpp in Android through 5.0 allow attackers to gain privileges or cause a denial of service (memory corruption) via vectors that trigger a large number of (1) file descriptors or (2) integer values.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Android | <=5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1474 has a high severity level due to the potential for privilege escalation and denial of service.
To fix CVE-2015-1474, update your Android device to a version higher than 5.0, as versions after this do not contain the vulnerability.
CVE-2015-1474 affects Google Android versions up to and including 5.0.
CVE-2015-1474 can be exploited to gain privileges or cause memory corruption, leading to denial of service.
CVE-2015-1474 is not specifically described as a remote vulnerability; it involves local exploitation through the GraphicBuffer manipulation.