CVE-2015-3835
Publication date 1 October 2015
Last updated 24 July 2024
Ubuntu priority
Description
Buffer overflow in the OMXNodeInstance::emptyBuffer function in omx/OMXNodeInstance.cpp in libstagefright in Android before 5.1.1 LMY48I allows attackers to execute arbitrary code via a crafted application, aka internal bug 20634516.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| android | ||
| 14.04 LTS trusty | Not in release | |
Notes
jdstrand
as with previous stagefright issues, this issue affects Ubuntu's android packages, but not in a way that is exposed to apps. See CVE-2015-1538 for details
References
Other references
- https://groups.google.com/forum/message/raw?msg=android-security-updates/Ugvu3fi6RQM/yzJvoTVrIQAJ
- https://android.googlesource.com/platform/frameworks/av/+/3cb1b6944e776863aea316e25fdc16d7f9962902
- https://android.googlesource.com/platform/frameworks/av/+/086d84f45ab7b64d1a7ed7ac8ba5833664a6a5ab
- https://www.cve.org/CVERecord?id=CVE-2015-3835