9.3 High
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:M/Au:N/C:C/I:C/A:C
7.7 High
AI Score
Confidence
Low
0.009 Low
EPSS
Percentile
82.4%
libutils in Android through 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted metadata in a (1) MP3 or (2) MP4 file, as demonstrated by an attack against use of libutils by libstagefright in Android 5.x.
CPE | Name | Operator | Version |
---|---|---|---|
google:android | google android | le | 5.1.1 |
www.securitytracker.com/id/1033725
blog.zimperium.com/zimperium-zlabs-is-raising-the-volume-new-vulnerability-processing-mp3mp4-media/
support.silentcircle.com/customer/en/portal/articles/2145864-privatos-1-1-12-release-notes
threatpost.com/stagefright-2-0-vulnerabilities-affect-1-billion-android-devices/114863/