vendor:
zeroltevzw
by:
Google Security Research
7,5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: zeroltevzw
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Android
2015
Memory Corruption when Media Scanning Occurs
The attached jpg, upsample.jpg can cause memory corruption when media scanning occurs. The vulnerability is caused by a buffer overflow in the WINKJ_DoIntegralUpsample+164 function of the libQjpeg.so library. The SIGSEGV signal is triggered when the WINKJ_SetupUpsample+228 function is called, which leads to a crash of the DCMService process.
Mitigation:
The vulnerability can be mitigated by applying the latest security patches.