CVE-2015-7894
HIGHSamsung Galaxy S6 Edge Firmware - Remote Code Execution via Crafted JPG Image
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-7894. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit demonstrates a memory corruption vulnerability in the DCMProvider service on Samsung devices, triggered by a malformed JPEG file. The crash occurs in libQjpeg.so, potentially allowing arbitrary code execution due to the program counter being set to a value from the JPEG file.
Description
The DCMProvider service in Samsung LibQjpeg on a Samsung SM-G925V device running build number LRX22G.G925VVRU1AOE2 allows remote attackers to cause a denial of service (segmentation fault and process crash) and execute arbitrary code via a crafted JPG.
Exploits (1)
This exploit demonstrates a memory corruption vulnerability in the DCMProvider service on Samsung devices, triggered by a malformed JPEG file. The crash occurs in libQjpeg.so, potentially allowing arbitrary code execution due to the program counter being set to a value from the JPEG file.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H