CVE Vulnerabilities

CVE-2016-3754

Published: Jul 11, 2016 | Modified: Jul 11, 2016
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu
LOW

mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 does not limit process-memory usage, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 28615448.

Affected Software

Name Vendor Start Version End Version
Android Google 4.0 (including) 4.0 (including)
Android Google 4.0.1 (including) 4.0.1 (including)
Android Google 4.0.2 (including) 4.0.2 (including)
Android Google 4.0.3 (including) 4.0.3 (including)
Android Google 4.0.4 (including) 4.0.4 (including)
Android Google 4.1 (including) 4.1 (including)
Android Google 4.1.2 (including) 4.1.2 (including)
Android Google 4.2 (including) 4.2 (including)
Android Google 4.2.1 (including) 4.2.1 (including)
Android Google 4.2.2 (including) 4.2.2 (including)
Android Google 4.3 (including) 4.3 (including)
Android Google 4.3.1 (including) 4.3.1 (including)
Android Google 4.4 (including) 4.4 (including)
Android Google 4.4.1 (including) 4.4.1 (including)
Android Google 4.4.2 (including) 4.4.2 (including)
Android Google 4.4.3 (including) 4.4.3 (including)
Android Google 5.0 (including) 5.0 (including)
Android Google 5.0.1 (including) 5.0.1 (including)
Android Google 5.1 (including) 5.1 (including)
Android Google 5.1.0 (including) 5.1.0 (including)
Android Google 6.0 (including) 6.0 (including)
Android Google 6.0.1 (including) 6.0.1 (including)
Android Ubuntu esm-apps/xenial *
Android Ubuntu trusty *
Android Ubuntu vivid/stable-phone-overlay *
Android Ubuntu wily *
Android Ubuntu xenial *
Android Ubuntu yakkety *
Android Ubuntu zesty *

References