CVE-2017-0674: Input Validation
Published Jul 5, 2017
·Updated
A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34231163.
Affected Software
6 affected components
Google Android=6.0
Google Android=6.0.1
Google Android=7.0
Google Android=7.1.1
Google Android=7.1.2
Google Android
Remediation
Patch Available
Event History
Jul 5, 2017
CVE Published
via Android·12:00 AM
Jul 6, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
Which Android releases are affected?
The affected releases are Android 6.0, 6.0.1, 7.0, 7.1.1, and 7.1.2.
2
What access or user interaction is required for exploitation?
The CVSS vector indicates local attack access, no privileges required, and user interaction required. Successful exploitation can affect confidentiality, integrity, and availability.
3
What should organizations do to remediate this issue?
A patch is available. Apply the relevant Android security update for affected devices.