First published: Sun Sep 11 2016(Updated: )
The decoder_peek_si_internal function in vp9/vp9_dx_iface.c in libvpx in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allows remote attackers to cause a denial of service (buffer over-read, and device hang or reboot) via a crafted media file, aka internal bug 30013856.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =4.0 | |
Google Android | =4.0.1 | |
Google Android | =4.0.2 | |
Google Android | =4.0.3 | |
Google Android | =4.0.4 | |
Google Android | =4.1 | |
Google Android | =4.1.2 | |
Google Android | =4.2 | |
Google Android | =4.2.1 | |
Google Android | =4.2.2 | |
Google Android | =4.3 | |
Google Android | =4.3.1 | |
Google Android | =4.4 | |
Google Android | =4.4.1 | |
Google Android | =4.4.2 | |
Google Android | =4.4.3 | |
Google Android | =5.0 | |
Google Android | =5.0.1 | |
Google Android | =5.1 | |
Google Android | =5.1.0 | |
Google Android | =6.0 | |
Google Android | =6.0.1 | |
Google Android | =7.0 |
https://android.googlesource.com/platform/external/libvpx/+/4974dcbd0289a2530df2ee2a25b5f92775df80da
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3881 has a CVSS score that indicates it can lead to a denial of service.
To fix CVE-2016-3881, you need to update your Android device to a version beyond the vulnerable ones listed in the description.
CVE-2016-3881 affects Android versions 4.0 through 6.x before September 2016 and 7.0 before September 2016.
CVE-2016-3881 is a buffer over-read vulnerability that may cause device hang or reboot.
CVE-2016-3881 can be exploited by remote attackers to cause denial of service.