Vulnerability Name: | CVE-2017-0543 (CCN-124408) | ||||||||||||||||
Assigned: | 2016-11-29 | ||||||||||||||||
Published: | 2017-04-07 | ||||||||||||||||
Updated: | 2017-07-11 | ||||||||||||||||
Summary: | A remote code execution vulnerability in libavc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-34097866. | ||||||||||||||||
CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) 6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
| ||||||||||||||||
Vulnerability Type: | CWE-119 | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-0543 Source: BID Type: Third Party Advisory, VDB Entry 97330 Source: CCN Type: BID-97330 Google Android Mediaserver Multiple Memory Corruption Vulnerabilities Source: SECTRACK Type: UNKNOWN 1038201 Source: CONFIRM Type: Issue Tracking, Patch, Third Party Advisory https://android.googlesource.com/platform/external/libavc/+/f634481e940421020e52f511c1fb34aac1db4b2f Source: CCN Type: Google Web site Android Source: XF Type: UNKNOWN android-cve20170543-code-exec(124408) Source: CCN Type: Android Open Source Project Android Security Bulletin—April 2017 Source: CONFIRM Type: Vendor Advisory https://source.android.com/security/bulletin/2017-04-01 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |