CVE-2017-0551: High severity Google Android vulnerability
A remote denial of service vulnerability in libavc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-34097231.
Affected Software
Remediation
Event History
Frequently Asked Questions
Which Android versions are affected?
The issue affects Android 6.0, 6.0.1, 7.0, and 7.1.1 in the Mediaserver libavc component.
What does an attacker need to exploit this issue?
An attacker needs to provide a specially crafted file and requires user interaction for that file to be processed. The CVSS vector indicates no privileges are required and local attack-vector conditions.
What is the likely impact if exploitation succeeds?
Successful exploitation can cause the device to hang or reboot, resulting in a denial of service. The listed CVSS impact affects availability only, with no stated confidentiality or integrity impact.
Is a fix available?
Yes. A patch is available; the referenced Android security bulletin is dated 2017-04-01.