Candidate: CVE-2015-3877 PublicDate: 2015-10-06 17:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3877 https://groups.google.com/forum/#!topic/android-security-updates/iv1BF0f0XY4 https://android.googlesource.com/platform/external/skia/+/55ad31336a6de7037139820558c5de834797c09e%5E!/#F0 Description: Skia, as used in Android before 5.1.1 LMY48T, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 20723696. Ubuntu-Description: Notes: sbeattie> skia/libskia does garner mentions in the libhybris source sbeattie> memory overwrite when downsampling interlaced gif images Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_android: upstream_android: released (5.1.1 LMY48T) precise_android: DNE trusty_android: ignored (code not compiled) trusty/esm_android: DNE (trusty was ignored [code not compiled]) vivid_android: ignored (code not compiled) vivid/stable-phone-overlay_android: ignored (code not compiled) vivid/ubuntu-core_android: DNE wily_android: ignored (code not compiled) devel_android: ignored (code not compiled)