CVE-2016-0841: Buffer Overflow
media/libmedia/mediametadataretriever.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 mishandles cleared service binders, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 26040840.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0841?
CVE-2016-0841 is considered a high-severity vulnerability due to its potential to allow remote code execution or denial of service.
What versions of Android are affected by CVE-2016-0841?
CVE-2016-0841 affects Android versions 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before April 1, 2016.
How do I fix CVE-2016-0841?
To fix CVE-2016-0841, users should update their Android devices to the latest security patch provided by Google.
What kind of attack can exploit CVE-2016-0841?
CVE-2016-0841 can be exploited by attackers to execute arbitrary code remotely or cause memory corruption leading to denial of service.
Is CVE-2016-0841 a local or remote vulnerability?
CVE-2016-0841 is a remote vulnerability, allowing attackers to exploit it without needing local access to the device.