CVE-2015-6575: Integer Overflow
SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I does not properly consider integer promotion, which allows remote attackers to execute arbitrary code or cause a denial of service (integer overflow and memory corruption) via crafted atoms in MP4 data, aka internal bug 20139950, a different vulnerability than CVE-2015-1538. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7915, CVE-2014-7916, and/or CVE-2014-7917.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6575?
CVE-2015-6575 is rated as critical due to its potential to allow remote code execution and denial of service.
How do I fix CVE-2015-6575?
To fix CVE-2015-6575, upgrade to Android version 5.1.1 LMY48I or later.
What type of attack can exploit CVE-2015-6575?
CVE-2015-6575 can be exploited through crafted MP4 data, leading to integer overflow and memory corruption.
Which versions of Android are affected by CVE-2015-6575?
CVE-2015-6575 affects all Android versions before 5.1.1 LMY48I.
Is there a public exploit available for CVE-2015-6575?
There is no specific public exploit detailed for CVE-2015-6575, but its vulnerability allows for arbitrary code execution if exploited.