CVE-2017-13230: Critical severity Google Android vulnerability
In hevc codec, there is an out-of-bounds write due to an incorrect bounds check with the i2picwidthinlumasamples value. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-65483665.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-13230?
CVE-2017-13230 has a high severity level due to its potential for remote escalation of privilege.
How do I fix CVE-2017-13230?
To fix CVE-2017-13230, update to the latest version of Android that addresses this vulnerability.
Who is affected by CVE-2017-13230?
CVE-2017-13230 affects users of Android versions 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, and 8.1.
Is user interaction required to exploit CVE-2017-13230?
Yes, user interaction is needed for the exploitation of CVE-2017-13230.
What component of Android is affected by CVE-2017-13230?
CVE-2017-13230 affects the HEVC codec within the Android operating system.