CVE-2016-0804: Buffer Overflow
The NuPlayer::GenericSource::notifyPreparedAndCleanup function in media/libmediaplayerservice/nuplayer/GenericSource.cpp in mediaserver in Android 5.x before 5.1.1 LMY49G and 6.x before 2016-02-01 improperly manages mDrmManagerClient objects, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 25070434.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0804?
CVE-2016-0804 has been classified with a high severity rating due to its potential to allow arbitrary code execution.
How do I fix CVE-2016-0804?
To mitigate CVE-2016-0804, users should update their Android system to version 5.1.1 LMY49G or later.
Which Android versions are affected by CVE-2016-0804?
CVE-2016-0804 affects Android versions 5.0, 5.0.1, 5.0.2, 5.1, 5.1.0, 5.1.1, 6.0, and 6.0.1.
What type of attack does CVE-2016-0804 enable?
CVE-2016-0804 allows remote attackers to execute arbitrary code on vulnerable Android devices.
Is there a patch available for CVE-2016-0804?
Yes, patches have been released as part of security updates for affected Android versions.