CVE-2017-13319: High severity android vulnerability
In pvmp3getmaindatasize of pvmp3getmaindatasize.cpp, there is a possible buffer overread due to a missing bounds check. This could lead to remote information disclosure of global static variables with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-13319?
CVE-2017-13319 is classified as a moderate vulnerability due to the potential for remote information disclosure.
How does CVE-2017-13319 manifest in affected software?
CVE-2017-13319 can lead to a buffer overread because of missing bounds checks in the affected Android versions.
Which Android versions are affected by CVE-2017-13319?
CVE-2017-13319 affects Google Android versions 7.0, 7.1.1, 7.1.2, 8.0, and 8.1.
Is user interaction required for exploiting CVE-2017-13319?
No, user interaction is not needed for the exploitation of CVE-2017-13319.
How can I mitigate CVE-2017-13319 in my Android device?
To mitigate CVE-2017-13319, ensure that your Android device is updated to a version that includes the relevant security patches.