HIGH
SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I does not properly consider integer promotion, which allows remote attackers to execute arbitrary code or cause a denial of service (integer overflow and memory corruption) via crafted atoms in MP4 data, aka internal bug 20139950, a different vulnerability than CVE-2015-1538
Published Oct 1, 2015
10.0
HIGHCVSS 2.0
EPSS 2.79%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.