CVE-2016-2429: Buffer Overflow
libFLAC/streamdecoder.c in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not prevent free operations on uninitialized memory, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted media file, aka internal bug 27211885.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2429?
CVE-2016-2429 has a severity rating that allows remote attackers to execute arbitrary code or cause a denial of service due to heap memory corruption.
How do I fix CVE-2016-2429?
To fix CVE-2016-2429, upgrade to Android versions 4.4.4, 5.0.2, 5.1.1, or later.
What versions of Android are affected by CVE-2016-2429?
CVE-2016-2429 affects Android versions 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x prior to May 1, 2016.
What impact does CVE-2016-2429 have on Android devices?
CVE-2016-2429 can lead to remote code execution or a system crash due to uninitialized memory access.
Is CVE-2016-2429 a local or remote vulnerability?
CVE-2016-2429 is a remote vulnerability, allowing attackers to exploit it from a distance without physical access to the device.