CVE-2017-0877: Input Validation
A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0. Android ID A-66372937.
Affected Software
Event History
Frequently Asked Questions
Which Android deployments are identified as affected?
Devices running Android 6.0 are identified as affected. The provided data does not state whether other Android versions, device models, or vendor builds are affected.
What does an attacker need to exploit this issue?
The CVSS vector indicates network attack vector, low attack complexity, no privileges required, and user interaction required. An attacker would need to induce a user to interact with attacker-controlled content or a delivery mechanism that reaches the vulnerable media framework.
Is a default Android 6.0 configuration known to be affected?
The data does not specify whether the vulnerable libavc code is enabled or reachable in a default Android 6.0 configuration.
What can be done if a patch cannot be applied immediately?
The provided information does not include temporary mitigations, detection guidance, or indicators that a device has already been exploited.