CVE-2015-3864
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 87%
from disclosure to weapon0 days
Published on NVDOct 1
1st PoCAug 18
metasploitAug 13
exploitation probability
87%top 1% of all CVEs
observed exploitation
nono source reports it
11 public exploit(s)
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android before 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted MPEG-4 data, aka internal bug 23034759. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3824.
Affected products
n/a · n/apublic PoCs found — 11✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/38226exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/40436exploitdbwww.exploit-db.com/exploits/39640unverifiedgithubgithub.com/eudemonics/scaredycat★ 17githubgithub.com/pwnaccelerator/stagefright-cve-2015-3864★ 3githubgithub.com/HenryVHuang/CVE-2015-3864★ 0githubgithub.com/Bhathiya404/Exploiting-Stagefright-Vulnerability-CVE-2015-3864★ 0githubgithub.com/Cmadhushanka/CVE-2015-3864-Exploitation★ 0cve_referencewww.exploit-db.com/exploits/38226/unverifiedcve_referencewww.exploit-db.com/exploits/40436/unverifiedcve_referencewww.exploit-db.com/exploits/39640/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://android.googlesource.com/platform/frameworks/av/+/6fe85f7e15203e48df2cc3e8e1c4bc6ad49dc968https://blog.zimperium.com/cve-2015-3864-metasploit-module-now-available-for-testing/https://blog.zimperium.com/reflecting-on-stagefright-patches/https://groups.google.com/forum/message/raw?msg=android-security-updates/1M7qbSvACjo/Y7jewiW1AwAJhttps://www.exploit-db.com/exploits/38226/https://www.exploit-db.com/exploits/39640/https://www.exploit-db.com/exploits/40436/http://www.securityfocus.com/bid/76682