Vulnerability Name: | CVE-2015-3827 (CCN-105689) | ||||||||
Assigned: | 2015-07-27 | ||||||||
Published: | 2015-07-27 | ||||||||
Updated: | 2017-09-21 | ||||||||
Summary: | The MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not validate the relationship between chunk sizes and skip sizes, which allows remote attackers to execute arbitrary code or cause a denial of service (integer underflow and memory corruption) via crafted MPEG-4 covr atoms, aka internal bug 20923261. | ||||||||
CVSS v3 Severity: | 9.8 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-189 CWE-119 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: Zimperium Mobile Security Blog, Monday, Jul 27 2015 at 13:02 Experts Found a Unicorn in the Heart of AndroidExperts Found a Unicorn in the Heart of Android Source: MITRE Type: CNA CVE-2015-3827 Source: CCN Type: CNNMoney (New York) July 28, 2015: 10:32 AM ET Android phones can be hacked with a simple text Source: CONFIRM Type: UNKNOWN http://www.huawei.com/en/psirt/security-advisories/hw-448928 Source: CCN Type: US-CERT VU#924951 Android Stagefright contains multiple vulnerabilities Source: BID Type: UNKNOWN 76052 Source: CCN Type: BID-76052 Google Stagefright Media Playback Engine Multiple Remote Code Execution Vulnerabilities Source: SECTRACK Type: UNKNOWN 1033094 Source: CCN Type: WIRED Security Hack Brief: The Android Text Attack Source: CONFIRM Type: UNKNOWN http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-448928.htm Source: CCN Type: Google Android GIT repositories android Git repositories Source: CONFIRM Type: Vendor Advisory https://android.googlesource.com/platform/frameworks/av/+/f4a88c8ed4f8186b3d6e2852993e063fc33ff231 Source: XF Type: UNKNOWN google-android-cve20153827-underflow(105689) Source: MLIST Type: Vendor Advisory [android-security-updates] 20150812 Nexus Security Bulletin (August 2015) Source: CCN Type: WhiteSource Vulnerability Database CVE-2015-3827 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |