CVE-2017-0549: High severity Google Android vulnerability
Published Apr 3, 2017
·Updated
A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33818508.
Affected Software
6 affected components
Google Android=6.0
Google Android=6.0.1
Google Android=7.0
Google Android=7.1.0
Google Android=7.1.1
Google Android
Remediation
Event History
Apr 3, 2017
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityAffected Software
Apr 7, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
Which Android versions are affected?
The affected versions listed are Android 6.0, 6.0.1, 7.0, and 7.1.1.
2
What must an attacker do to trigger the issue?
The attacker must cause the device to process a specially crafted file. Successful exploitation can hang or reboot the device, resulting in denial of service.
3
Is a fix available?
Yes. A patch is available for this issue.