CVE-2015-3828

Publication date 1 October 2015

Last updated 24 July 2024


Ubuntu priority

Negligible

Why this priority?

Description

The MPEG4Extractor::parse3GPPMetaData function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not enforce a minimum size for UTF-16 strings containing a Byte Order Mark (BOM), which allows remote attackers to execute arbitrary code or cause a denial of service (integer underflow and memory corruption) via crafted 3GPP metadata, aka internal bug 20923261, a related issue to CVE-2015-3826.

Read the notes from the security team

Status

Package Ubuntu Release Status
android 15.10 wily Ignored
15.04 vivid Ignored
14.04 LTS trusty Not in release
12.04 LTS precise Not in release

Notes


jdstrand

please see CVE-2015-1538 for details until more information is public Ubuntu 14.04 is affected but no supported images use it