CVE-2016-1621: Buffer Overflow
libvpx in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.0 before 2016-03-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, related to libwebm/mkvparser.cpp and other files, aka internal bug 23452792.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1621?
CVE-2016-1621 has a high severity rating due to its potential for execution of arbitrary code or denial of service.
How do I fix CVE-2016-1621?
To fix CVE-2016-1621, update the Android operating system to a version released after March 1, 2016.
What impact does CVE-2016-1621 have on devices?
Devices affected by CVE-2016-1621 may experience memory corruption leading to crashes or the execution of malicious code.
Which versions of Android are affected by CVE-2016-1621?
CVE-2016-1621 affects Android versions 4.x, 5.x, and 6.0 up to March 2016.
Are there any workarounds for CVE-2016-1621?
While updating the OS is the best solution, avoiding the playback of untrusted media files can temporarily mitigate the risk of CVE-2016-1621.