Multiple integer overflows in the BnHDCP::onTransact function in media/libmedia/IHDCP.cpp in libstagefright in Android before 5.1.1 LMY48I allow attackers to execute arbitrary code via a crafted application that uses HDCP encryption, leading to a heap-based buffer overflow, aka internal bug 20222489.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Android | * | 5.1 (including) | |
Android | Ubuntu | devel | * |
Android | Ubuntu | trusty | * |
Android | Ubuntu | vivid | * |
Android | Ubuntu | vivid/stable-phone-overlay | * |
Android | Ubuntu | wily | * |