CVE-2016-0837: Buffer Overflow
MPEG4Extractor.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read and memory corruption) via a crafted media file, aka internal bug 27208621.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0837?
CVE-2016-0837 has a critical severity rating due to its potential for remote code execution and memory corruption.
How do I fix CVE-2016-0837?
To fix CVE-2016-0837, update your Android device to a version 4.4.4, 5.0.2, 5.1.1, or later.
Which Android versions are affected by CVE-2016-0837?
CVE-2016-0837 affects Android versions from 4.0 up to 6.0.1 prior to the April 2016 security update.
What types of attacks are possible with CVE-2016-0837?
CVE-2016-0837 can be exploited to execute arbitrary code or cause a denial of service through crafted media files.
Is CVE-2016-0837 related to any specific Android component?
Yes, CVE-2016-0837 is linked to vulnerabilities in the libstagefright component of Android's media server.