CVE-2015-3834: Buffer Overflow
Multiple integer overflows in the BnHDCP::onTransact function in media/libmedia/IHDCP.cpp in libstagefright in Android before 5.1.1 LMY48I allow attackers to execute arbitrary code via a crafted application that uses HDCP encryption, leading to a heap-based buffer overflow, aka internal bug 20222489.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3834?
CVE-2015-3834 is classified as high severity due to its potential to allow arbitrary code execution on affected Android devices.
How do I fix CVE-2015-3834?
To fix CVE-2015-3834, update your Android device to version 5.1.1 LMY48I or later, where the vulnerability is patched.
What causes CVE-2015-3834?
CVE-2015-3834 is caused by multiple integer overflows in the BnHDCP::onTransact function, leading to heap-based buffer overflow vulnerabilities.
Which versions of Android are affected by CVE-2015-3834?
CVE-2015-3834 affects all Android versions prior to 5.1.1 LMY48I.
Can CVE-2015-3834 be exploited remotely?
Yes, CVE-2015-3834 can be exploited by attackers through a crafted application that uses HDCP encryption.