CVE-2017-13177: Buffer Overflow
In several functions of libhevc, NEON registers are not preserved. This could lead to remote code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68320413.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-13177?
CVE-2017-13177 has a high severity rating as it allows for potential remote code execution without user interaction.
How do I fix CVE-2017-13177?
To mitigate CVE-2017-13177, users should upgrade their Android devices to versions that have patched this vulnerability.
Which versions of Android are affected by CVE-2017-13177?
CVE-2017-13177 affects Android versions 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, and 8.1.
Is user interaction required for exploiting CVE-2017-13177?
No, exploiting CVE-2017-13177 does not require any user interaction.
What component of Android does CVE-2017-13177 affect?
CVE-2017-13177 affects the libhevc component of the Android operating system.