CVE-2016-3878 PUBLISHED

decoder/ih264d_api.c in mediaserver in Android 6.x before 2016-09-01 mishandles the case of decoding zero MBs, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 29493002.

EPSS 0.27% · 50.5th percentile

Risk Scores

EPSS Score
0.27%
50.5th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSandroid0, 20150818-1500-0ubuntu2, 20150818-1500-0ubuntu3

Timeline

References

Open in Interactive Console →