Back

CRITICAL

libvpx: remote code execution via crafted media file

Published Mar 12, 2016

Description

libvpx in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.0 before 2016-03-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, related to libwebm/mkvparser.cpp and other files, aka internal bug 23452792.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Chrome
Published Mar 12, 2016
Updated Aug 5, 2024
Reserved Jan 12, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Mar 14, 2016