CVE-2015-6636: Buffer Overflow
mediaserver in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bugs 25070493 and 24686670.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6636?
CVE-2015-6636 has a high severity as it allows remote attackers to execute arbitrary code or cause a denial of service.
How do I fix CVE-2015-6636?
To fix CVE-2015-6636, update your Android device to version 5.1.1 LMY49F or later.
What versions of Android are affected by CVE-2015-6636?
CVE-2015-6636 affects Android versions 5.0, 5.1.1 before LMY49F, and 6.0 before January 1, 2016.
What can attackers do with CVE-2015-6636?
Attackers exploiting CVE-2015-6636 can execute arbitrary code or cause memory corruption that leads to a denial of service.
Is there a workaround for CVE-2015-6636?
There are no specific workarounds for CVE-2015-6636; the recommended action is to update to a safe version of Android.