First published: Mon Apr 02 2018(Updated: )
In SvoxSsmlParser and startElement of svox_ssml_parser.cpp, there is a possible out of bounds write due to an uninitialized buffer. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-69177126.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =6.0 | |
Google Android | =6.0.1 | |
Google Android | =7.0 | |
Google Android | =7.1.1 | |
Google Android | =7.1.2 | |
Google Android | =8.0 | |
Google Android | =8.1 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-13285 is classified as a high-severity vulnerability that can lead to remote code execution.
To fix CVE-2017-13285, ensure that your Android device is updated to a version that includes the patch provided in the security bulletin.
CVE-2017-13285 affects Android versions 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, and 8.1.
Yes, CVE-2017-13285 can be exploited remotely with no user interaction required.
CVE-2017-13285 impacts the SvoxSsmlParser and the startElement function in the svox_ssml_parser.cpp file.