UBUNTU-CVE-2016-0824

Source
https://ubuntu.com/security/CVE-2016-0824
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2016/UBUNTU-CVE-2016-0824.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2016-0824
Upstream
  • CVE-2016-0824
Published
2016-03-12T21:59:00Z
Modified
2025-09-08T16:43:35Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

libmpeg2 in libstagefright in Android 6.x before 2016-03-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via crafted Bitstream data, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 25765591.

References

Affected packages

Ubuntu:16.04:LTS / android

Package

Name
android
Purl
pkg:deb/ubuntu/android@20160307-0742-0ubuntu3?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20160307-0742-0ubuntu3

Affected versions

Other
20150818-1500-0ubuntu2
20150818-1500-0ubuntu3

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "android",
            "binary_version": "20160307-0742-0ubuntu3"
        },
        {
            "binary_name": "android-copyright",
            "binary_version": "20160307-0742-0ubuntu3"
        },
        {
            "binary_name": "android-emulator",
            "binary_version": "20160307-0742-0ubuntu3"
        },
        {
            "binary_name": "ubuntu-emulator-images",
            "binary_version": "20160307-0742-0ubuntu3"
        },
        {
            "binary_name": "ubuntu-emulator-runtime",
            "binary_version": "20160307-0742-0ubuntu3"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2016/UBUNTU-CVE-2016-0824.json"