CVE-2015-7897
high
CVSS v3
—
CVSS v2
7.5
VIR risk
7.5
Description
The media scanning functionality in the face recognition library in android.media.process in Samsung Galaxy S6 Edge before G925VVRU4B0G9 allows remote attackers to gain privileges or cause a denial of service (memory corruption) via a crafted BMP image file.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — http://googleprojectzero.blogspot.com/2015/11/hack-galaxy-hunting-bugs-in-samsung.html
Exploits
Exploit-DB
- EDB-38611 · dos · android
References
- http://googleprojectzero.blogspot.com/2015/11/hack-galaxy-hunting-bugs-in-samsung.html
- http://packetstormsecurity.com/files/134199/Samsung-Galaxy-S6-Android.media.process-Face-Recognition-Memory-Corruption.html
- https://code.google.com/p/google-security-research/issues/detail?id=499&q=samsung
- https://www.exploit-db.com/exploits/38611/
- http://googleprojectzero.blogspot.com/2015/11/hack-galaxy-hunting-bugs-in-samsung.html
- http://packetstormsecurity.com/files/134199/Samsung-Galaxy-S6-Android.media.process-Face-Recognition-Memory-Corruption.html
- https://code.google.com/p/google-security-research/issues/detail?id=499&q=samsung
- https://www.exploit-db.com/exploits/38611/
CWEs
CWE-119
Verify integrity in audit chain (admin only). AS-IS.