CVE-2015-3864
CVE-2015-3864
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android before 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted MPEG-4 data, aka internal bug 23034759. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3824.
Produtos afetados
n/a · n/aPoCs públicas encontradas — 11
githubgithub.com/eudemonics/scaredycat★ 17githubgithub.com/pwnaccelerator/stagefright-cve-2015-3864★ 3githubgithub.com/Bhathiya404/Exploiting-Stagefright-Vulnerability-CVE-2015-3864★ 0githubgithub.com/Cmadhushanka/CVE-2015-3864-Exploitation★ 0githubgithub.com/HenryVHuang/CVE-2015-3864★ 0cve_referencewww.exploit-db.com/exploits/38226/não verificadoexploitdbwww.exploit-db.com/exploits/39640não verificadocve_referencewww.exploit-db.com/exploits/39640/não verificadocve_referencewww.exploit-db.com/exploits/40436/não verificadoexploitdbwww.exploit-db.com/exploits/38226não verificadoexploitdbwww.exploit-db.com/exploits/40436não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
https://android.googlesource.com/platform/frameworks/av/+/6fe85f7e15203e48df2cc3e8e1c4bc6ad49dc968https://blog.zimperium.com/cve-2015-3864-metasploit-module-now-available-for-testing/https://blog.zimperium.com/reflecting-on-stagefright-patches/https://groups.google.com/forum/message/raw?msg=android-security-updates/1M7qbSvACjo/Y7jewiW1AwAJhttps://www.exploit-db.com/exploits/38226/https://www.exploit-db.com/exploits/39640/https://www.exploit-db.com/exploits/40436/http://www.securityfocus.com/bid/76682