PT-2015-2225 · Google+1 · Android+2

Joshua J. Drake

·

Published

2015-08-09

·

Updated

2017-09-21

·

CVE-2015-3824

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android versions prior to 5.1.1 LMY48I
Description The issue is related to the MPEG4Extractor::parseChunk function in the libstagefright library, which does not properly restrict size addition. This allows remote attackers to execute arbitrary code or cause a denial of service due to integer overflow and memory corruption via a crafted MPEG-4 tx3g atom. The vulnerability can be exploited by sending specially crafted data in the MPEG-4 format, potentially leading to remote code execution or a denial of service.
Recommendations For Android versions prior to 5.1.1 LMY48I, update to version 5.1.1 LMY48I or later to resolve the issue. As a temporary workaround, consider restricting the use of the libstagefright library until a patch is available. Avoid using the MPEG4Extractor::parseChunk function in the affected library to minimize the risk of exploitation.

Fix

RCE

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-11571
CVE-2015-3824

Affected Products

Android
Huawei Vrp
Libstagefright