CVE-2015-3864
Summary
| CVE | CVE-2015-3864 |
|---|---|
| State | PUBLISHED |
| Assigner | google_android |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-10-01 00:59:31 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android before 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted MPEG-4 data, aka internal bug 23034759. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3824. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Google Android 5.0.1 - Metaphor Stagefright (ASLR Bypass) - Android remote Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| Reflecting on Stagefright Patches › Zimperium Mobile Security Blog | af854a3a-2127-422b-91ae-364da2661108 | blog.zimperium.com | |
| 6fe85f7e15203e48df2cc3e8e1c4bc6ad49dc968 - platform/frameworks/av - Git at Google | af854a3a-2127-422b-91ae-364da2661108 | android.googlesource.com | Vendor Advisory |
| Android libstagefright - Integer Overflow Remote Code Execution | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| Android Open Source Project = Details | af854a3a-2127-422b-91ae-364da2661108 | groups.google.com | Vendor Advisory |
| Google Android 5.0 < 5.1.1 - 'Stagefright' .MP4 tx3g Integer Overflow (Metasploit) - Android remote Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| CVE-2015-3864 Metasploit module now available for testing › Zimperium Mobile Security Blog | af854a3a-2127-422b-91ae-364da2661108 | blog.zimperium.com | Release Notes, Third Party Advisory |
| Google Android Stagefright CVE-2015-3864 Incomplete Fix Integer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.