CVE Vulnerabilities

CVE-2015-1538

Published: Oct 01, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
NEGLIGIBLE
root.io logo minimus.io logo echo.ai logo

Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I allows remote attackers to execute arbitrary code via crafted atoms in MP4 data that trigger an unchecked multiplication, aka internal bug 20139950, a related issue to CVE-2015-4496.

Affected Software

NameVendorStart VersionEnd Version
AndroidGoogle*5.1 (including)
AndroidUbuntudevel*
AndroidUbuntutrusty*
AndroidUbuntuupstream*
AndroidUbuntuvivid*
AndroidUbuntuvivid/stable-phone-overlay*
AndroidUbuntuwily*

References