CVE-2017-0859: High severity Google Android vulnerability
Published Nov 16, 2017
·Updated
Another vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36075131.
Affected Software
5 affected components
Google Android=6.0
Google Android=6.0.1
Google Android=7.0
Google Android=7.1.1
Google Android=7.1.2
Remediation
Event History
Nov 16, 2017
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
DescriptionWeakness
Frequently Asked Questions
1
Which Android releases should be prioritized for remediation?
The affected versions listed are Android 7.0, 7.1.1, and 7.1.2. A patch is available.
2
What access does an attacker need to exploit this issue?
The CVSS vector indicates network access, low attack complexity, no required privileges, and no user interaction. The scope is unchanged.
3
What is the expected security impact?
The CVSS assessment indicates high availability impact, with no confidentiality or integrity impact recorded. The listed base score is 7.8 (High).
4
How can I track this issue in Android security records?
Use Android ID A-36075131 when correlating the issue with Android security documentation or patch records.