CVE-2017-0409
Description
A remote code execution vulnerability in libstagefright could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses this library. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-31999646.
CWE
- (none)
Affected
- Google Inc. / Android — v=Android-6.0 [affected]; v=Android-6.0.1 [affected]; v=Android-7.0 [affected]; v=Android-7.1.1 [affected]
CVSS
- (none)
References
- http://www.securitytracker.com/id/1037798 vdb-entry, x_refsource_SECTRACK
- http://www.securityfocus.com/bid/96091 vdb-entry, x_refsource_BID
- https://source.android.com/security/bulletin/2017-02-01.html x_refsource_CONFIRM
Source
cvelistV5-main/cves/2017/0xxx/CVE-2017-0409.json