CVE-2017-13323: Integer Overflow
In String16 of String16.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege in an unprivileged process with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-13323?
CVE-2017-13323 has a severity level classified as high due to the potential for local privilege escalation.
How do I fix CVE-2017-13323?
To mitigate CVE-2017-13323, users should update their Android devices to the latest security patches provided by Google.
Which versions of Android are affected by CVE-2017-13323?
CVE-2017-13323 affects Android versions 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, and 8.1.
Is user interaction required to exploit CVE-2017-13323?
No, user interaction is not needed to exploit CVE-2017-13323, making it particularly concerning.
What are the potential impacts of CVE-2017-13323?
The potential impact of CVE-2017-13323 is an out of bounds write which can lead to local escalation of privilege in an unprivileged process.