Loading HuntDB...

GHSA-259j-9g27-vvvh

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

A remote code execution vulnerability in FLACExtractor.cpp in libstagefright in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34970788.

Related CVEs

Key Information

GHSA ID
GHSA-259j-9g27-vvvh
Published
May 17, 2022 2:44 AM
Last Modified
May 17, 2022 2:44 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 3, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.