CVE-2017-13283: Critical severity Google Android vulnerability
In avrcctrlparsvendorrsp of bluetooth avrcpctrl, there is a possible out of bounds write on the stack due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-71603410.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-13283?
CVE-2017-13283 has a severity that may allow remote code execution without user interaction.
How do I fix CVE-2017-13283?
To fix CVE-2017-13283, update your Android device to the latest security patch provided by Google.
What products are affected by CVE-2017-13283?
CVE-2017-13283 affects Android versions 7.0, 7.1.1, 7.1.2, 8.0, and 8.1.
Is user interaction required to exploit CVE-2017-13283?
No, user interaction is not required for exploiting CVE-2017-13283.
What type of vulnerability is CVE-2017-13283?
CVE-2017-13283 is an out of bounds write vulnerability that can lead to remote code execution.