CVE-2015-1538
Summary
| CVE | CVE-2015-1538 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-10-01 00:59:06 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I allows remote attackers to execute arbitrary code via crafted atoms in MP4 data that trigger an unchecked multiplication, aka internal bug 20139950, a related issue to CVE-2015-4496. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Android Stagefright - Remote Code Execution - Exploits Database | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| Google Stagefright Media Playback Engine Multiple Remote Code Execution Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| 2434839bbd168469f80dd9a22f1328bc81046398 - platform/frameworks/av - Git at Google | af854a3a-2127-422b-91ae-364da2661108 | android.googlesource.com | Vendor Advisory |
| Libstagefright Integer Overflow Check Bypass ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | |
| Security Advisory - Stagefright Vulnerability in Multiple Huawei Android Products | af854a3a-2127-422b-91ae-364da2661108 | www1.huawei.com | |
| Security Advisory - Stagefright Vulnerability in Multiple Huawei Android Products | af854a3a-2127-422b-91ae-364da2661108 | www.huawei.com | |
| Google Android MMS Media Processing Flaw Lets Remote Users Execute Arbitrary Code on the Target System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| groups.google.com/forum/message/raw | af854a3a-2127-422b-91ae-364da2661108 | groups.google.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.