CVE-2017-13257: Use After Free
In btapandatabufindcback of btapanact.cc there is a use after free that can result in an out of bounds read of memory allocated via malloc. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-67110692.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-13257?
CVE-2017-13257 is classified as a moderate severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2017-13257?
To fix CVE-2017-13257, users should update their Android devices to the latest security patch provided by Google.
What type of vulnerability is CVE-2017-13257?
CVE-2017-13257 is a use after free vulnerability that can lead to an out of bounds memory read.
Who is affected by CVE-2017-13257?
CVE-2017-13257 affects Android versions 5.1.1 through 8.1.
Is user interaction required for exploiting CVE-2017-13257?
Yes, user interaction is necessary for the exploitation of CVE-2017-13257.