First published: Mon Apr 18 2016(Updated: )
Multiple stack-based buffer underflows in decoder/ih264d_parse_cavlc.c in mediaserver in Android 6.x before 2016-04-01 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 26399350.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | =6.0 | |
Android | =6.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0840 has a high severity rating due to its potential to allow remote code execution and denial of service.
To fix CVE-2016-0840, update your Android device to version 6.0.1 or later if it is available.
CVE-2016-0840 affects Android 6.0 and 6.0.1 devices prior to the April 2016 security patch.
CVE-2016-0840 enables remote attackers to execute arbitrary code or cause memory corruption through crafted media files.
CVE-2016-0840 is not a current threat on devices that have been updated to the patched versions post-April 2016.