CVE-2016-2428: Buffer Overflow
libAACdec/src/aacdecdrc.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not properly limit the number of threads, which allows remote attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via a crafted media file, aka internal bug 26751339.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2428?
CVE-2016-2428 is considered a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2016-2428?
To fix CVE-2016-2428, update your Android system to a version 4.4.4, 5.0.2, 5.1.1, or later.
Which applications are affected by CVE-2016-2428?
CVE-2016-2428 affects the mediaserver component in Android versions prior to 4.4.4, 5.0.2, 5.1.1, and 6.0.1.
Can CVE-2016-2428 lead to a denial of service?
Yes, CVE-2016-2428 can lead to a denial of service by causing stack memory corruption.
What exploits are known for CVE-2016-2428?
Exploits for CVE-2016-2428 may allow attackers to execute arbitrary code remotely.