CVE-2015-3864: Critical severity android vulnerability
Published Oct 1, 2015
·Updated
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android before 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted MPEG-4 data, aka internal bug 23034759. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3824.
Affected Software
1 affected component
Google Android<=5.1
Event History
Oct 1, 2015
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3864?
CVE-2015-3864 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2015-3864?
To mitigate CVE-2015-3864, update to Android version 5.1.1 or higher.
3
What causes CVE-2015-3864?
CVE-2015-3864 is caused by an integer underflow in the MPEG4Extractor::parseChunk function.
4
Which Android versions are affected by CVE-2015-3864?
CVE-2015-3864 affects all Android versions prior to 5.1.1 LMY48M.
5
Can CVE-2015-3864 be exploited remotely?
Yes, CVE-2015-3864 can be exploited remotely via crafted MPEG-4 data.