CVE-2017-0550: High severity Google Android vulnerability
A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33933140.
Affected Software
Remediation
Event History
Frequently Asked Questions
What does an attacker need to do to trigger the denial of service?
The attacker needs to cause the device to process a specially crafted file. Exploitation requires user interaction, while the CVSS vector indicates no attacker privileges are required.
Which Android releases are identified as affected?
Android 6.0, 6.0.1, 7.0, and 7.1.1 are listed as affected.
What is the expected impact if exploitation succeeds?
A successful attack can cause the device to hang or reboot. The reported impact is denial of service, with no confidentiality or integrity impact indicated by the CVSS vector.
Is a fix available?
Yes. A patch is available for this issue.