CVE-2017-0775: Medium severity Google Android vulnerability
A denial of service vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62673179.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Android media framework (libstagefright)to a version that resolves this vulnerability.Fixed in 8.0 - Upgrade
Upgrade
Android media framework (libstagefright)to a version that resolves this vulnerability.Fixed in 7.1.2 - Upgrade
Upgrade
Android media framework (libstagefright)to a version that resolves this vulnerability.Fixed in 7.1.1 - Upgrade
Upgrade
Android media framework (libstagefright)to a version that resolves this vulnerability.Fixed in 7.0 - Upgrade
Upgrade
Android media framework (libstagefright)to a version that resolves this vulnerability.Fixed in 6.0.1 - Upgrade
Upgrade
Android media framework (libstagefright)to a version that resolves this vulnerability.Fixed in 6.0 - Upgrade
Upgrade
Android media framework (libstagefright)to a version that resolves this vulnerability.Fixed in 5.1.1 - Upgrade
Upgrade
Android media framework (libstagefright)to a version that resolves this vulnerability.Fixed in 5.0.2 - Upgrade
Upgrade
Android media framework (libstagefright)to a version that resolves this vulnerability.Fixed in 4.4.4
Event History
Frequently Asked Questions
What is the severity of CVE-2017-0775?
CVE-2017-0775 has been classified as a high severity denial of service vulnerability.
How do I fix CVE-2017-0775?
To fix CVE-2017-0775, users should update their Android devices to a patched version that resolves the vulnerability.
Which Android versions are affected by CVE-2017-0775?
CVE-2017-0775 affects Android versions 4.4.4 through 8.0.
What types of attacks can exploit CVE-2017-0775?
CVE-2017-0775 can be exploited through crafted media files that lead to a denial of service.
Is there a workaround for CVE-2017-0775?
There is no official workaround for CVE-2017-0775, and the best mitigation is to upgrade affected devices.