CVE-2017-13279: Medium severity Google Android vulnerability
In M3UParser::parse of M3UParser.cpp, there is a memory resource exhaustion due to a large loop of pushing items into a vector. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68399439.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-13279?
CVE-2017-13279 has a severity rating of medium, as it could lead to a remote denial of service.
How do I fix CVE-2017-13279?
To fix CVE-2017-13279, update your Android device to the latest software version provided by Google that addresses this vulnerability.
What versions of Android are affected by CVE-2017-13279?
CVE-2017-13279 affects Android versions 6.0 through 8.1.
What type of exploitation is possible with CVE-2017-13279?
CVE-2017-13279 can be exploited via user interaction, resulting in memory resource exhaustion.
Does CVE-2017-13279 require special privileges to exploit?
No, CVE-2017-13279 does not require additional execution privileges to exploit.