Vulnerability Name: | CVE-2015-3828 (CCN-105691) | ||||||||
Assigned: | 2015-07-27 | ||||||||
Published: | 2015-07-27 | ||||||||
Updated: | 2017-09-21 | ||||||||
Summary: | The MPEG4Extractor::parse3GPPMetaData function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not enforce a minimum size for UTF-16 strings containing a Byte Order Mark (BOM), which allows remote attackers to execute arbitrary code or cause a denial of service (integer underflow and memory corruption) via crafted 3GPP metadata, aka internal bug 20923261, a related issue to CVE-2015-3826. | ||||||||
CVSS v3 Severity: | 9.8 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-189 CWE-119 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: Zimperium Mobile Security Blog, Monday, Jul 27 2015 at 13:02 Experts Found a Unicorn in the Heart of AndroidExperts Found a Unicorn in the Heart of Android Source: MITRE Type: CNA CVE-2015-3828 Source: CCN Type: CNNMoney (New York) July 28, 2015: 10:32 AM ET Android phones can be hacked with a simple text Source: CONFIRM Type: UNKNOWN http://www.huawei.com/en/psirt/security-advisories/hw-448928 Source: CCN Type: US-CERT VU#924951 Android Stagefright contains multiple vulnerabilities Source: BID Type: UNKNOWN 76052 Source: CCN Type: BID-76052 Google Stagefright Media Playback Engine Multiple Remote Code Execution Vulnerabilities Source: SECTRACK Type: UNKNOWN 1033094 Source: CCN Type: WIRED Security Hack Brief: The Android Text Attack Source: CONFIRM Type: UNKNOWN http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-448928.htm Source: CCN Type: Google Android GIT repositories android Git repositories Source: CONFIRM Type: Vendor Advisory https://android.googlesource.com/platform/frameworks/av/+/f4f7e0c102819f039ebb1972b3dba1d3186bc1d1 Source: XF Type: UNKNOWN google-android-cve20153828-underflow(105691) Source: MLIST Type: Vendor Advisory [android-security-updates] 20150812 Nexus Security Bulletin (August 2015) Source: CCN Type: WhiteSource Vulnerability Database CVE-2015-3828 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |