Denial of Service Vulnerability in Samsung LibQjpeg on Samsung Devices
CVE-2015-7894
8.8HIGH
Key Information:
- Vendor
Samsung
- Status
- Vendor
- CVE Published:
- 9 August 2017
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2015-7894?
The DCMProvider service in the Samsung LibQjpeg library on the Samsung SM-G925V device is susceptible to a denial of service attack. By sending a specially crafted JPG file, a remote attacker can trigger a segmentation fault, leading to the crash of the LibQjpeg process. This vulnerability poses a serious risk as it allows unauthorized users to potentially execute arbitrary code, compromising device integrity and security.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.