First published: Tue Oct 06 2015(Updated: )
libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bugs 23016072, 23248776, 23247055, 22845824, 22008959, 21814993, 21048776, 20718524, 20674674, 22388975, 20674086, 21443020, and 22077698, a different vulnerability than CVE-2015-7716.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | <=5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3873 is classified as a critical vulnerability due to its potential to execute arbitrary code and cause denial of service.
To fix CVE-2015-3873, update your Android device to version 5.1.1 LMY48T or later.
CVE-2015-3873 affects all Android versions prior to 5.1.1 LMY48T.
CVE-2015-3873 can be exploited using crafted media files that lead to memory corruption.
CVE-2015-3873 specifically affects the libstagefright component in Android.