CVE-2015-3824: Buffer Overflow
The MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not properly restrict size addition, which allows remote attackers to execute arbitrary code or cause a denial of service (integer overflow and memory corruption) via a crafted MPEG-4 tx3g atom, aka internal bug 20923261.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3824?
CVE-2015-3824 is classified as a critical vulnerability due to the potential for remote code execution and denial of service.
How do I fix CVE-2015-3824?
To fix CVE-2015-3824, update your Android device to version 5.1.1 or later, as earlier versions are affected.
What types of attacks can exploit CVE-2015-3824?
CVE-2015-3824 can be exploited by remote attackers through crafted MPEG-4 files leading to integer overflow and memory corruption.
Which versions of Android are affected by CVE-2015-3824?
CVE-2015-3824 affects all versions of Android before 5.1.1 LMY48I.
What components are involved in CVE-2015-3824?
CVE-2015-3824 specifically involves the MPEG4Extractor::parseChunk function in the libstagefright component of Android.