CVE-2016-0839: Buffer Overflow
postproc/volumelistener.c in mediaserver in Android 6.x before 2016-04-01 mishandles deleted effect context, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 25753245.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0839?
The severity of CVE-2016-0839 is considered high due to potential remote code execution and denial of service risks.
How do I fix CVE-2016-0839?
To fix CVE-2016-0839, update your Android device to the latest security patch available after April 2016.
What versions of Android are affected by CVE-2016-0839?
CVE-2016-0839 affects Android versions 6.0 and 6.0.1 prior to the April 2016 security updates.
What types of attacks can exploit CVE-2016-0839?
CVE-2016-0839 can be exploited through crafted media files that lead to memory corruption and arbitrary code execution.
Who can be impacted by CVE-2016-0839?
Users of Android devices running versions 6.0 and 6.0.1 could be impacted by CVE-2016-0839 if they play malicious media files.