AddVorbisCodecInfo Function in Matroska/MatroskaExtractor.cpp in Libstagefright Vulnerability (CVE-2015-3861)
Publish date: 06 de abril de 2016
Gravedad: Medio
Identificadores de CVE : CVE-2015-3861
Fecha recomendada: 06 de abril de 2016
Descripción
This vulnerability pertains to the multiple integer overflows in the addVorbisCodecInfo function in matroska/MatroskaExtractor.cpp in libstagefright in mediaserver in Android before 5.1.1 LMY48M. When exploited successfully, it could allow remote attackers denial of service (DoS).
Trend Micro researcher Wish Wu disclosed details about this vulnerability to Google. The said company acknowledged Wu’s research contribution.
Revelación de la información
Apply associated Trend Micro DPI Rules.