CVE-2016-0836: Buffer Overflow
Stack-based buffer overflow in decoder/impeg2dvld.c in mediaserver in Android 6.x before 2016-04-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 25812590.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0836?
CVE-2016-0836 has a critical severity rating due to its potential for remote code execution and denial of service via crafted media files.
How do I fix CVE-2016-0836?
To fix CVE-2016-0836, update your Android device to the latest version that has addressed this vulnerability.
Which versions of Android are affected by CVE-2016-0836?
CVE-2016-0836 affects Android versions 6.0 and 6.0.1 released before April 1, 2016.
What type of attack does CVE-2016-0836 enable?
CVE-2016-0836 allows remote attackers to execute arbitrary code or cause memory corruption via specially crafted media files.
Is there a way to mitigate the risk of CVE-2016-0836?
Mitigation strategies for CVE-2016-0836 include avoiding the opening of unknown or untrusted media files on affected Android devices.