CVE-2016-0840: Buffer Overflow
Multiple stack-based buffer underflows in decoder/ih264dparsecavlc.c in mediaserver in Android 6.x before 2016-04-01 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 26399350.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0840?
CVE-2016-0840 has a high severity rating due to its potential to allow remote code execution and denial of service.
How do I fix CVE-2016-0840?
To fix CVE-2016-0840, update your Android device to version 6.0.1 or later if it is available.
Who is affected by CVE-2016-0840?
CVE-2016-0840 affects Android 6.0 and 6.0.1 devices prior to the April 2016 security patch.
What type of attack does CVE-2016-0840 enable?
CVE-2016-0840 enables remote attackers to execute arbitrary code or cause memory corruption through crafted media files.
Is CVE-2016-0840 still a threat?
CVE-2016-0840 is not a current threat on devices that have been updated to the patched versions post-April 2016.