CVE-2017-0878: Input Validation
Published Dec 4, 2017
·Updated
A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 8.0. Android ID A-65186291.
Affected Software
2 affected components
Google Android=8.0
Google Android
Event History
Dec 4, 2017
CVE Published
via Android·12:00 AM
Dec 6, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What conditions are required to exploit this vulnerability?
The CVSS vector indicates network-based exploitation with low attack complexity and no privileges required, but it requires user interaction. Successful exploitation can result in remote code execution with high impact to confidentiality, integrity, and availability.
2
Which Android version is identified as affected?
The provided data identifies Android 8.0 as affected. The issue is in the Android media framework component libhevc.
3
How can I identify this issue in Android security tracking?
This vulnerability is tracked as Android ID A-65186291 and CVE-2017-0878. The supplied references include the Android December 2017 security bulletin and the associated libhevc source change.