Denial of Service Vulnerability in Samsung LibQjpeg on Samsung Devices
CVE-2015-7894
Key Information:
- Vendor
Samsung
- Status
- Vendor
- CVE Published:
- 9 August 2017
Badges
What is CVE-2015-7894?
The DCMProvider service in the Samsung LibQjpeg library on the Samsung SM-G925V device is susceptible to a denial of service attack. By sending a specially crafted JPG file, a remote attacker can trigger a segmentation fault, leading to the crash of the LibQjpeg process. This vulnerability poses a serious risk as it allows unauthorized users to potentially execute arbitrary code, compromising device integrity and security.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
8% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved