CVE-2017-13197: Buffer Overflow
In the ihevcdparseslice.c function, slave threads are not joined if there is an error. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-64784973.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-13197?
CVE-2017-13197 is categorized as a medium severity vulnerability due to its potential for remote denial of service.
How do I fix CVE-2017-13197?
To fix CVE-2017-13197, update your Android device to the latest version that includes security patches addressing this vulnerability.
Which versions of Android are affected by CVE-2017-13197?
CVE-2017-13197 affects Android versions 6.0, 6.0.1, and multiple versions up to 8.1.
Can CVE-2017-13197 be exploited without user interaction?
Yes, CVE-2017-13197 can be exploited without user interaction, making it particularly critical.
What components of Android are impacted by CVE-2017-13197?
CVE-2017-13197 impacts the ihevcd_parse_slice.c function, leading to possible denial of service of critical system processes.