CVE-2016-0838: Buffer Overflow
Sonivox in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not check for a negative number of samples, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, related to arm-wt-22k/libsrc/easwtengine.c and arm-wt-22k/libsrc/easwtsynth.c, aka internal bug 26366256.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0838?
CVE-2016-0838 is considered a critical vulnerability as it allows remote attackers to execute arbitrary code or cause a denial of service.
How do I fix CVE-2016-0838?
To fix CVE-2016-0838, users should update their Android devices to version 6.0.1 or later as patches are included in this update.
Which versions of Android are affected by CVE-2016-0838?
CVE-2016-0838 affects Android versions 4.x prior to 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x prior to April 1, 2016.
What types of attacks can CVE-2016-0838 enable?
CVE-2016-0838 can enable remote code execution or memory corruption attacks through specially crafted media files.
Is there a public exploit available for CVE-2016-0838?
While specific public exploits are not mentioned, the nature of CVE-2016-0838 suggests that skilled attackers could develop exploits using the vulnerability to cause significant harm.