Vulnerability Name: | CVE-2017-0406 (CCN-122023) | ||||||||||||||||
Assigned: | 2016-11-29 | ||||||||||||||||
Published: | 2017-02-06 | ||||||||||||||||
Updated: | 2017-07-25 | ||||||||||||||||
Summary: | A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. This affects the libhevc library. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32915871. | ||||||||||||||||
CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) 6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
7.7 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
| ||||||||||||||||
Vulnerability Type: | CWE-119 | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: CCN Type: Google Web site Android Source: MITRE Type: CNA CVE-2017-0406 Source: BID Type: Third Party Advisory, VDB Entry 96046 Source: CCN Type: BID-96046 Google Android Mediaserver Multiple Remote Code Execution Vulnerabilities Source: SECTRACK Type: UNKNOWN 1037798 Source: XF Type: UNKNOWN android-cve20170406-code-exec(122023) Source: CCN Type: Android Open Source Project Android Security Bulletin—February 2017 Source: CONFIRM Type: Vendor Advisory https://source.android.com/security/bulletin/2017-02-01.html | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |