CVE-2016-3871 describes multiple buffer overflow vulnerabilities in the libstagefright component of Android's mediaserver, specifically within the MP3 decoding functionality. This flaw affects various Android versions, including 4.x, 5.0.x, 5.1.x, 6.x, and 7.0, prior to their respective September 2016 security updates. An attacker could exploit this by tricking a user into installing a crafted application, leading to privilege escalation. The vulnerability carries a high CVSSv3 score of 7.8, indicating a significant risk. Its attack vector is local, requiring user interaction (UI:R) to install a malicious application, but the attack complexity is low (AC:L). Successful exploitation could result in high impacts to confidentiality, integrity, and availability (C:H/I:H/A:H), allowing an attacker to gain elevated privileges on the affected device. Despite its severity, there is no evidence of active exploitation in the wild, and it is not listed in CISA's KEV catalog. No public exploit code, such as Metasploit or ExploitDB modules, is available, and there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0CPE matchmatch criteria | cpe:2.3:o:google:android:4.0:*:*:*:*:*:*:* | ||
4.0.1CPE matchmatch criteria | cpe:2.3:o:google:android:4.0.1:*:*:*:*:*:*:* | ||
4.0.2CPE matchmatch criteria | cpe:2.3:o:google:android:4.0.2:*:*:*:*:*:*:* | ||
4.0.3CPE matchmatch criteria | cpe:2.3:o:google:android:4.0.3:*:*:*:*:*:*:* | ||
4.0.4CPE matchmatch criteria | cpe:2.3:o:google:android:4.0.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.