First published: Wed Nov 27 2024(Updated: )
In pvmp3_get_main_data_size of pvmp3_get_main_data_size.cpp, there is a possible buffer overread due to a missing bounds check. This could lead to remote information disclosure of global static variables with no additional execution privileges needed. User interaction is not needed for exploitation.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =7.0 | |
Google Android | =7.1.1 | |
Google Android | =7.1.2 | |
Google Android | =8.0 | |
Google Android | =8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-13319 is classified as a moderate vulnerability due to the potential for remote information disclosure.
CVE-2017-13319 can lead to a buffer overread because of missing bounds checks in the affected Android versions.
CVE-2017-13319 affects Google Android versions 7.0, 7.1.1, 7.1.2, 8.0, and 8.1.
No, user interaction is not needed for the exploitation of CVE-2017-13319.
To mitigate CVE-2017-13319, ensure that your Android device is updated to a version that includes the relevant security patches.