~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
Candidate: CVE-2015-3834
PublicDate: 2015-09-30
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3834
 https://groups.google.com/forum/message/raw?msg=android-security-updates/Ugvu3fi6RQM/yzJvoTVrIQAJ
 https://android.googlesource.com/platform/frameworks/av/+/c82e31a7039a03dca7b37c65b7890ba5c1e18ced
Description:
 Multiple integer overflows in the BnHDCP::onTransact function in
 media/libmedia/IHDCP.cpp in libstagefright in Android before 5.1.1 LMY48I
 allow attackers to execute arbitrary code via a crafted application that
 uses HDCP encryption, leading to a heap-based buffer overflow, aka internal
 bug 20222489.
Ubuntu-Description:
Notes:
 jdstrand> as with previous stagefright issues, this issue affects Ubuntu's
  android packages, but not in a way that is exposed to apps.  See
  CVE-2015-1538 for details
Bugs:
Priority: negligible
Discovered-by:
Assigned-to:

Patches_android:
upstream_android: needs-triage
precise_android: DNE
trusty_android: ignored
vivid_android: ignored
vivid/stable-phone-overlay_android: ignored
vivid/ubuntu-core_android: DNE
wily_android: ignored
devel_android: ignored