CVE-2015-7890: Buffer Overflow
Published Feb 12, 2020
·Updated
Multiple buffer overflows in the esawrite function in /dev/seirenin the Exynos Seiren Audio driver, as used in Samsung S6 Edge, allow local users to cause a denial of service (memory corruption) via a large (1) buffer or (2) size parameter.
Affected Software
2 affected components
Samsung Galaxy S6 Edge Firmware
Samsung Galaxy S6 Edge
Event History
Feb 12, 2020
CVE Published
via MITRE·02:54 PM
Data Sourced
via MITRE·02:54 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this security flaw?
The vulnerability ID of this security flaw is CVE-2015-7890.
2
What is the severity rating of CVE-2015-7890?
CVE-2015-7890 has a severity rating of 5.5 (medium).
3
How does CVE-2015-7890 affect Samsung Galaxy S6 Edge?
CVE-2015-7890 affects Samsung Galaxy S6 Edge firmware, potentially causing a denial of service due to memory corruption.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by local users through the esa_write function in /dev/seiren, by providing a large buffer or size parameter.
5
Are there any fixes or patches available for CVE-2015-7890?
Unfortunately, specific fixes or patches for CVE-2015-7890 are not mentioned in the provided references.