CVE-2016-0842: Buffer Overflow
The H.264 decoder in libstagefright in Android 6.x before 2016-04-01 mishandles Memory Management Control Operation (MMCO) data, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 25818142.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0842?
CVE-2016-0842 is considered a critical vulnerability that can lead to remote code execution or denial of service.
How do I fix CVE-2016-0842?
To mitigate CVE-2016-0842, update your Android device to a patched version of Android released after April 1, 2016.
Who is affected by CVE-2016-0842?
CVE-2016-0842 affects all Android 6.0 and 6.0.1 devices prior to the security update released on April 1, 2016.
What type of attack does CVE-2016-0842 enable?
CVE-2016-0842 allows remote attackers to execute arbitrary code or cause memory corruption by using specially crafted media files.
Is CVE-2016-0842 a local or remote vulnerability?
CVE-2016-0842 is a remote vulnerability that can be exploited through malicious media files accessed over the network.