CVE-2015-1539
Multiple integer underflows in the ESDS::parseESDescriptor function in ESDS.cpp in libstagefright in Android before 5.1.1 LMY48I allow remote attackers to execute arbitrary code via crafted ESDS atoms, aka internal bug 20139950, a related issue to…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 85.8%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple integer underflows in the ESDS::parseESDescriptor function in ESDS.cpp in libstagefright in Android before 5.1.1 LMY48I allow remote attackers to execute arbitrary code via crafted ESDS atoms, aka internal bug 20139950, a related issue to CVE-2015-4493.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 85.79% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-189
- Affected
- google/android
- Source
- cve@mitre.org
References
- http://www.huawei.com/en/psirt/security-advisories/hw-448928
- http://www.securityfocus.com/bid/76052
- http://www.securitytracker.com/id/1033094
- http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-448928.htm
- https://android.googlesource.com/platform/frameworks/av/+/5e751957ba692658b7f67eb03ae5ddb2cd3d970cVendor Advisory
- https://groups.google.com/forum/message/raw?msg=android-security-updates/Ugvu3fi6RQM/yzJvoTVrIQAJVendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/hw-448928
- http://www.securityfocus.com/bid/76052
- http://www.securitytracker.com/id/1033094
- http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-448928.htm
- https://android.googlesource.com/platform/frameworks/av/+/5e751957ba692658b7f67eb03ae5ddb2cd3d970cVendor Advisory
- https://groups.google.com/forum/message/raw?msg=android-security-updates/Ugvu3fi6RQM/yzJvoTVrIQAJVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.