Memory Corruption Vulnerability in Samsung Galaxy S6's LibQJpeg Library
CVE-2015-7896
6.5MEDIUM
What is CVE-2015-7896?
The LibQJpeg library in the Samsung Galaxy S6 prior to the October 2015 maintenance release is susceptible to memory corruption vulnerabilities. Malicious actors may exploit this weakness by crafting specific image files to induce a denial of service condition on the device, potentially leading to unexpected crashes (SIGSEGV). This vulnerability highlights the critical need for users to ensure their devices are updated to mitigate potential risks.
References
EPSS Score
11% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved