Android Mediaserver Remote Execution Of Arbitrary Code Vulnerabilities
10 Jun. 2016
Summary
mediaserver in Android 6.x before 2016-03-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, related to decoder/ih264d_parse_islice.c and decoder/ih264d_parse_pslice.c
Vulnerable Systems:
*Android 6.x before 2016-03-01
Immune Systems:
*Android 6.x after 2016-03-01
The mediaserver in Android allows attackers to obtain sensitive TrustZone secure-storage information by leveraging kernel access, as demonstrated by obtaining Signature or SignatureOrSystem access.Allows unauthorized disclosure of information