PT-2016-2558 · Google · Android

Published

2016-08-05

·

Updated

2016-11-28

·

CVE-2016-3829

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Android versions prior to 2016-08-01
Description The issue is related to the ih264d decoder in the mediaserver of Android, where certain structure members are not initialized. This allows remote attackers to cause a denial of service, resulting in a device hang or reboot, via a crafted media file.
Recommendations For Android versions prior to 2016-08-01, update the operating system to a version released after 2016-08-01 to resolve the issue. As a temporary workaround, consider avoiding the use of crafted media files that could exploit this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-01950
CVE-2016-3829

Affected Products

Android