CVE-2017-13194: Input Validation
Published Jan 12, 2018
·Updated
A vulnerability in the Android media framework (libvpx) related to odd frame width. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-64710201.
Affected Software
12 affected componentsFixes available
Google Android=5.1.1
Google Android=6.0
Google Android=6.0.1
Google Android=7.0
Google Android=7.1.1
Google Android=7.1.2
Google Android=8.0
Google Android=8.1
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
debian/libvpx
1.9.0-1+deb11u31.9.0-1+deb11u51.12.0-1+deb12u41.12.0-1+deb12u51.15.0-2.11.15.0-2.1+deb13u11.16.0-3
Remediation
Event History
Jan 12, 2018
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
DescriptionWeakness
Jan 11, 2024
Data Sourced
via Launchpad·10:28 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·08:46 PM
RemedyDescriptionSeverityAffected Software
Feb 22, 2026
Data Sourced
via Debian·08:49 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-13194?
The severity of CVE-2017-13194 is classified as a high-severity vulnerability.
2
How do I fix CVE-2017-13194?
To fix CVE-2017-13194, you should upgrade to the latest version of libvpx or the affected Android versions recommended by the vendor.
3
Which versions of Android are affected by CVE-2017-13194?
CVE-2017-13194 affects Android versions 7.0, 7.1.1, 7.1.2, 8.0, and 8.1.
4
Is CVE-2017-13194 a remote code execution vulnerability?
Yes, CVE-2017-13194 can potentially allow remote code execution through crafted media files.
5
Are Debian systems impacted by CVE-2017-13194?
Yes, Debian systems running specified versions of libvpx are impacted by CVE-2017-13194.