CVE-2015-3824
EUVD-2015-386001.10.2015, 00:59
The MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not properly restrict size addition, which allows remote attackers to execute arbitrary code or cause a denial of service (integer overflow and memory corruption) via a crafted MPEG-4 tx3g atom, aka internal bug 20923261.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| android | 𝑥 ≤ 5.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References