CVE-2016-1621
published 2016-03-12CVE-2016-1621: libvpx in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.0 before 2016-03-01 allows remote attackers to execute arbitrary code or…
PriorityP349critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
5.90%
92.4th percentile
libvpx in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.0 before 2016-03-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, related to libwebm/mkvparser.cpp and other files, aka internal bug 23452792.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libvpx | < libvpx 1.6.1-1 (bookworm) | libvpx 1.6.1-1 (bookworm) |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pjpg-8wjw-xmv3: libvpx in mediaserver in Android 4
ghsa_unreviewed·2022-05-17
CVE-2016-1621 [CRITICAL] CWE-119 GHSA-pjpg-8wjw-xmv3: libvpx in mediaserver in Android 4
libvpx in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.0 before 2016-03-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, related to libwebm/mkvparser.cpp and other files, aka internal bug 23452792.
OSV
CVE-2016-1621: libvpx in mediaserver in Android 4
osv·2016-03-12·CVSS 9.8
CVE-2016-1621 [CRITICAL] CVE-2016-1621: libvpx in mediaserver in Android 4
libvpx in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.0 before 2016-03-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, related to libwebm/mkvparser.cpp and other files, aka internal bug 23452792.
Red Hat
libvpx: remote code execution via crafted media file
vendor_redhat·2016-03-14·CVSS 9.8
CVE-2016-1621 [CRITICAL] CWE-20 libvpx: remote code execution via crafted media file
libvpx: remote code execution via crafted media file
libvpx in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.0 before 2016-03-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, related to libwebm/mkvparser.cpp and other files, aka internal bug 23452792.
Package: libvpx (Red Hat Enterprise Linux 6) - Not affected
Package: libvpx (Red Hat Enterprise Linux 7) - Not affected
Android
CVE-2016-1621: Android Security Bulletin 2016-03-01
CVE: CVE-2016-1621
Severity: CRITICAL
Affected AOSP versions: 4
vendor_android·2016-03-01·CVSS 9.8
CVE-2016-1621 [CRITICAL] CVE-2016-1621: Android Security Bulletin 2016-03-01
CVE: CVE-2016-1621
Severity: CRITICAL
Affected AOSP versions: 4
Android Security Bulletin 2016-03-01
CVE: CVE-2016-1621
Severity: CRITICAL
Affected AOSP versions: 4.4.4, 5.0.2, 5.1.1, 6.0
Debian
CVE-2016-1621: libvpx - libvpx in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and ...
vendor_debian·2016·CVSS 9.8
CVE-2016-1621 [CRITICAL] CVE-2016-1621: libvpx - libvpx in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and ...
libvpx in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.0 before 2016-03-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, related to libwebm/mkvparser.cpp and other files, aka internal bug 23452792.
Scope: local
bookworm: resolved (fixed in 1.6.1-1)
bullseye: resolved (fixed in 1.6.1-1)
forky: resolved (fixed in 1.6.1-1)
sid: resolved (fixed in 1.6.1-1)
trixie: resolved (fixed in 1.6.1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-1621 compat-libvpx1: libvpx: remote code execution via crafted media file [fedora-23]
bugzilla·2016-03-16·CVSS 9.8
CVE-2016-1621 [CRITICAL] CVE-2016-1621 compat-libvpx1: libvpx: remote code execution via crafted media file [fedora-23]
CVE-2016-1621 compat-libvpx1: libvpx: remote code execution via crafted media file [fedora-23]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: add-trac
Bugzilla
CVE-2016-1621 libvpx: remote code execution via crafted media file [epel-5]
bugzilla·2016-03-16·CVSS 9.8
CVE-2016-1621 [CRITICAL] CVE-2016-1621 libvpx: remote code execution via crafted media file [epel-5]
CVE-2016-1621 libvpx: remote code execution via crafted media file [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: add-tracking-bugs]
D
Bugzilla
CVE-2016-1621 libvpx: remote code execution via crafted media file [fedora-all]
bugzilla·2016-03-16·CVSS 9.8
CVE-2016-1621 [CRITICAL] CVE-2016-1621 libvpx: remote code execution via crafted media file [fedora-all]
CVE-2016-1621 libvpx: remote code execution via crafted media file [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions o
Bugzilla
CVE-2016-1621 libvpx: remote code execution via crafted media file
bugzilla·2016-03-16·CVSS 9.8
CVE-2016-1621 [CRITICAL] CVE-2016-1621 libvpx: remote code execution via crafted media file
CVE-2016-1621 libvpx: remote code execution via crafted media file
A vulnerability was found in libvpx. A maliciously crafted media file allows remote attackers to execute arbitrary code or cause a denial of service.
Upstream fix:
https://android.googlesource.com/platform/external/libvpx/+/04839626ed859623901ebd3a5fd483982186b59d%5E!/#F1
References:
http://lwn.net/Vulnerabilities/680036/
Discussion:
Created compat-libvpx1 tracking bugs for this issue:
Affects: fedora-23 [bug 1318188]
---
Created libvpx tracking bugs for this issue:
Affects: fedora-all [bug 1318187]
Affects: epel-5 [bug 1318189]
---
There does not seem to be any technical details public about this issue. There is this Android security bulletin:
http://source.android.com/security/bulletin/2016-03-01.html#remote
arXiv
Hey Google, What Exactly Do Your Security Patches Tell Us? A Large-Scale Empirical Study on Android Patched Vulnerabilities
arxiv_fulltext·2019-05-22
Hey Google, What Exactly Do Your Security Patches Tell Us? A Large-Scale Empirical Study on Android Patched Vulnerabilities
1.55cm
[1]
\@fnsymbol#1
Hey Google, What Exactly Do Your Security Patches Tell Us?\ Large-Scale Empirical Study on Android Patched Vulnerabilities
Sadegh Farhang Sadegh Farhang and Mehmet Bahadir Kirdan equally contributed to this work.
Pennsylvania State University
[email protected]
Mehmet Bahadir Kirdan 1
Technical University of Munich
[email protected]
Aron Laszka
University of Houston
[email protected]
Jens Grossklags
Technical University of Munich
[email protected]
## Abstract
Android has the largest market share among smartphone platforms worldwide with more than one billion active devices.
Like other platforms, security patches play a pivotal role in keeping Android devices safe from the exploitation of known vulnerabilities. Previous research efforts have documente
http://lists.fedoraproject.org/pipermail/package-announce/2016-March/179128.htmlhttp://source.android.com/security/bulletin/2016-03-01.htmlhttp://www.securityfocus.com/bid/84239https://android.googlesource.com/platform/external/libvpx/+/04839626ed859623901ebd3a5fd483982186b59dhttps://android.googlesource.com/platform/external/libvpx/+/5a9753fca56f0eeb9f61e342b2fccffc364f9426https://android.googlesource.com/platform/frameworks/av/+/5a6788730acfc6fd8f4a6ef89d2c376572a26b55https://security.gentoo.org/glsa/201603-09http://lists.fedoraproject.org/pipermail/package-announce/2016-March/179128.htmlhttp://source.android.com/security/bulletin/2016-03-01.htmlhttp://www.securityfocus.com/bid/84239https://android.googlesource.com/platform/external/libvpx/+/04839626ed859623901ebd3a5fd483982186b59dhttps://android.googlesource.com/platform/external/libvpx/+/5a9753fca56f0eeb9f61e342b2fccffc364f9426https://android.googlesource.com/platform/frameworks/av/+/5a6788730acfc6fd8f4a6ef89d2c376572a26b55https://security.gentoo.org/glsa/201603-09
2016-03-12
Published