First published: Mon Apr 18 2016(Updated: )
post_proc/volume_listener.c in mediaserver in Android 6.x before 2016-04-01 mishandles deleted effect context, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 25753245.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | =6.0 | |
Android | =6.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-0839 is considered high due to potential remote code execution and denial of service risks.
To fix CVE-2016-0839, update your Android device to the latest security patch available after April 2016.
CVE-2016-0839 affects Android versions 6.0 and 6.0.1 prior to the April 2016 security updates.
CVE-2016-0839 can be exploited through crafted media files that lead to memory corruption and arbitrary code execution.
Users of Android devices running versions 6.0 and 6.0.1 could be impacted by CVE-2016-0839 if they play malicious media files.