First published: Fri Jun 11 2021(Updated: )
An improper input validation vulnerability in sdfffd_parse_chunk_FVER() in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =8.1 | |
Google Android | =9.0 | |
Google Android | =10.0 | |
Google Android | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25386 has a severity rating that indicates a high risk of exploitation due to improper input validation.
To fix CVE-2021-25386, update to the latest version of the libsdffextractor library as recommended by your software provider.
CVE-2021-25386 affects Google Android versions 8.1, 9.0, 10.0, and 11.0.
Yes, CVE-2021-25386 can allow attackers to execute arbitrary code on the mediaextractor process.
CVE-2021-25386 impacts the sdfffd_parse_chunk_FVER() function in the libsdffextractor library.