CVE-2017-0555: Infoleak
Published Apr 3, 2017
·Updated
An information disclosure vulnerability in libavc in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access data without permission. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33551775.
Affected Software
6 affected components
Google Android=6.0
Google Android=6.0.1
Google Android=7.0
Google Android=7.1.0
Google Android=7.1.1
Google Android
Event History
Apr 3, 2017
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityAffected Software
Apr 7, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-0555?
The severity of CVE-2017-0555 is rated as medium with a CVSS score of 5.5.
2
How do I fix CVE-2017-0555?
To fix CVE-2017-0555, update your Android device to the latest available version that addresses this vulnerability.
3
What type of vulnerability is CVE-2017-0555?
CVE-2017-0555 is an information disclosure vulnerability.
4
Which Android versions are affected by CVE-2017-0555?
CVE-2017-0555 affects Android versions 6.0, 6.0.1, 7.0, and 7.1.1.
5
What can a malicious application do with CVE-2017-0555?
A local malicious application can exploit CVE-2017-0555 to access data outside of its permission levels.