First published: Thu Oct 01 2015(Updated: )
Multiple buffer overflows in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I allow remote attackers to execute arbitrary code via invalid size values of NAL units in MP4 data, aka internal bug 19641538.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | <=5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3832 is considered critical as it allows remote code execution through buffer overflows.
To fix CVE-2015-3832, update your Android device to version 5.1.1 LMY48I or later.
CVE-2015-3832 affects Android versions prior to 5.1.1 LMY48I.
Yes, CVE-2015-3832 can be exploited remotely through specially crafted MP4 files.
CVE-2015-3832 exposes Android devices to potential unauthorized access and control, compromising user data and privacy.