CVE-2017-0538: Buffer Overflow
A remote code execution vulnerability in libavc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33641588.
Affected Software
Remediation
Event History
Frequently Asked Questions
Which Android versions and component are affected?
Devices running Android 6.0, 6.0.1, 7.0, or 7.1.1 are identified as affected. The vulnerable component runs in the Mediaserver process during media file and data processing.
What does exploitation require?
An attacker needs to get a specially crafted media file or data processed by the device. The CVSS vector indicates no privileges are required, but user interaction is required.
What is the potential impact of successful exploitation?
Successful exploitation can corrupt memory and potentially execute code in the Mediaserver process. The stated impact includes high confidentiality, integrity, and availability impact.
What remediation is available?
A patch is available. The supplied remediation information does not describe a workaround or mitigation for systems that cannot be patched immediately.