First published: Tue Nov 03 2015(Updated: )
mediaserver in Android 4.4 through 5.x before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23881715, a different vulnerability than CVE-2015-6608 and CVE-2015-8073.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =4.4 | |
Google Android | =5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8072 has a high severity level due to its potential for remote code execution and denial of service.
The recommended fix for CVE-2015-8072 is to update your Android device to version 5.1.1 LMY48X or higher.
CVE-2015-8072 affects Android versions 4.4, 5.0, and up to 6.0 before November 1, 2015.
CVE-2015-8072 can enable remote attackers to execute arbitrary code or cause a denial of service through crafted media files.
Yes, CVE-2015-8072 is a different vulnerability than CVE-2015-6608 and CVE-2015-8073.