CVE-2015-3836: Buffer Overflow
The Parsewave function in arm-wt-22k/libsrc/easmdls.c in the Sonivox DLS-to-EAS converter in Android before 5.1.1 LMY48I does not reject a negative value for a certain size field, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via crafted XMF data, aka internal bug 21132860.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3836?
CVE-2015-3836 is classified as a high-severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2015-3836?
To mitigate CVE-2015-3836, upgrade to Android version 5.1.1 LMY48I or later.
What types of attacks can exploit CVE-2015-3836?
CVE-2015-3836 can be exploited via crafted XM files resulting in arbitrary code execution or denial of service.
Which versions of Android are affected by CVE-2015-3836?
CVE-2015-3836 affects Android versions prior to 5.1.1 LMY48I.
Is CVE-2015-3836 related to buffer overflow vulnerabilities?
Yes, CVE-2015-3836 involves a buffer overflow vulnerability due to improper handling of negative size field values.