CVE-2015-3877: Buffer Overflow
Published Oct 6, 2015
·Updated
Skia, as used in Android before 5.1.1 LMY48T, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 20723696.
Affected Software
1 affected component
Google Android<=5.1
Event History
Oct 6, 2015
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3877?
CVE-2015-3877 has a high severity rating due to its potential for remote code execution and denial of service.
2
How do I fix CVE-2015-3877?
The recommended fix for CVE-2015-3877 is to update Android to version 5.1.1 or later to mitigate the vulnerability.
3
What types of attacks can be carried out exploiting CVE-2015-3877?
Exploiting CVE-2015-3877 can allow attackers to execute arbitrary code or cause a denial of service through crafted media files.
4
What versions of Android are affected by CVE-2015-3877?
CVE-2015-3877 affects all versions of Android prior to 5.1.1 LMY48T.
5
Is there a workaround for CVE-2015-3877?
There are no widely recommended workarounds for CVE-2015-3877; updating to a non-vulnerable version is the best approach.