MEDIUM
An information disclosure vulnerability in id3/ID3.cpp in libstagefright in Mediaserver could enable a local malicious application to access data outside of its permission levels
Published Jan 12, 2017
5.5
MEDIUMCVSS 3.0
EPSS 0.47%
Description
An information disclosure vulnerability in id3/ID3.cpp in libstagefright in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32377688.
Affected products
-
- Version Android-4.4.4StatusaffectedConstraints-
- Version Android-5.0.2StatusaffectedConstraints-
- Version Android-5.1.1StatusaffectedConstraints-
- Version Android-6.0StatusaffectedConstraints-
- Version Android-6.0.1StatusaffectedConstraints-
- Version Android-7.0StatusaffectedConstraints-
- Version Android-7.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Google Inc. | Android | n/a |
|
OR
- 4.0
- 4.0.1
- 4.0.2
- 4.0.3
- 4.0.4
- 4.1
- 4.1.2
- 4.2
- 4.2.1
- 4.2.2
- 4.3
- 4.3.1
- 4.4
- 4.4.1
- 4.4.2
- 4.4.3
- 4.4.4
- 5.0
- 5.0.1
- 5.0.2
- 5.1
- 5.1.0
- 5.1.1
- 6.0
- 6.0.1
- 7.0
- 7.1.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- http://www.securityfocus.com/bid/95232 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://android.googlesource.com/platform/frameworks/av/+/7a3246b870ddd11861eda2ab458b11d723c7f62c x_refsource_CONFIRMIssue TrackingPatch
- https://source.android.com/security/bulletin/2017-01-01.html x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/95232 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://android.googlesource.com/platform/frameworks/av/+/7a3246b870ddd11861eda2ab458b11d723c7f62c | x_refsource_CONFIRMIssue TrackingPatch | |
| https://source.android.com/security/bulletin/2017-01-01.html | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner google_android
Published Jan 12, 2017
Updated Aug 5, 2024
Reserved Nov 29, 2016
Link CVE-2017-0397
CISA Vulnrichment
Updated n/a