CVE-2015-6602
Publication date 2 October 2015
Last updated 24 July 2024
Ubuntu priority
Description
libutils in Android through 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted metadata in a (1) MP3 or (2) MP4 file, as demonstrated by an attack against use of libutils by libstagefright in Android 5.x.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| android | ||
| 14.04 LTS trusty | Not in release | |
Notes
References
Other references
- https://threatpost.com/stagefright-2-0-vulnerabilities-affect-1-billion-android-devices/114863/
- https://blog.zimperium.com/zimperium-zlabs-is-raising-the-volume-new-vulnerability-processing-mp3mp4-media/
- https://groups.google.com/forum/#!topic/android-security-updates/iv1BF0f0XY4
- https://android.googlesource.com/platform/system/core/+/5b85b1d40d619c2064d321364f212ebfeb6ba185%5E!/#F0
- https://android.googlesource.com/platform/system/core/+/e0dce90b0de2b2b7c2baae8035f810a55526effb%5E!/#F0
- https://www.cve.org/CVERecord?id=CVE-2015-6602