HIGH
In MediaPlayerService::Client::notify of MediaPlayerService.cpp, there is a possible use after free
Published Apr 4, 2018
7.8
HIGHCVSS 3.0
EPSS 0.45%
Description
In MediaPlayerService::Client::notify of MediaPlayerService.cpp, there is a possible use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-70546581.
Affected products
-
- Version 6.0StatusaffectedConstraints-
- Version 6.0.1StatusaffectedConstraints-
- Version 7.0StatusaffectedConstraints-
- Version 7.1.1StatusaffectedConstraints-
- Version 7.1.2StatusaffectedConstraints-
- Version 8.0StatusaffectedConstraints-
- Version 8.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Google Inc. | Android | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (1)
- https://source.android.com/security/bulletin/2018-04-01 x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://source.android.com/security/bulletin/2018-04-01 | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner google_android
Published Apr 4, 2018
Updated Sep 16, 2024
Reserved Aug 23, 2017
Link CVE-2017-13278
CISA Vulnrichment
Updated n/a