pazhanivel07 / frameworks_av-CVE-2020-0242_CVE-2020-0243

Other
0 stars 0 forks source link

CVE-2016-3754 (High) detected in avandroid-10.0.0_r37 #34

Open mend-bolt-for-github[bot] opened 2 years ago

mend-bolt-for-github[bot] commented 2 years ago

CVE-2016-3754 - High Severity Vulnerability

Vulnerable Library - avandroid-10.0.0_r37

Library home page: https://android.googlesource.com/platform/frameworks/av

Found in HEAD commit: 3817576ceacd1f81d53c0f1b5eec2a5cbecff7c3

Found in base branch: master

Vulnerable Source Files (3)

/media/libmedia/MediaUtils.h /media/libmedia/MediaUtils.h /media/libmedia/MediaUtils.h

Vulnerability Details

mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 does not limit process-memory usage, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 28615448.

Publish Date: 2016-07-11

URL: CVE-2016-3754

CVSS 3 Score Details (7.5)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: None - Integrity Impact: None - Availability Impact: High

For more information on CVSS3 Scores, click here.


Step up your Open Source Security Game with Mend here

mend-bolt-for-github[bot] commented 1 year ago

:information_source: This issue was automatically re-opened by Mend because the vulnerable library in the specific branch(es) has been detected in the Mend inventory.