CVE-2017-0589
Summary
| CVE | CVE-2017-0589 |
|---|---|
| State | PUBLISHED |
| Assigner | google_android |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-05-12 15:29:01 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34897036. |
Risk And Classification
Primary CVSS: v3.0 7.8 HIGH from [email protected]
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Problem Types: CWE-119 | Remote code execution
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 7.8 | HIGH | CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 9.3 | AV:N/AC:M/Au:N/C:C/I:C/A:C |
CVSS v3.0 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Android | 5.0 | All | All | All | |
| Operating System | Android | 5.0.1 | All | All | All | |
| Operating System | Android | 5.0.2 | All | All | All | |
| Operating System | Android | 5.1 | All | All | All | |
| Operating System | Android | 5.1.0 | All | All | All | |
| Operating System | Android | 5.1.1 | All | All | All | |
| Operating System | Android | 6.0 | All | All | All | |
| Operating System | Android | 6.0.1 | All | All | All | |
| Operating System | Android | 7.0 | All | All | All | |
| Operating System | Android | 7.1.0 | All | All | All | |
| Operating System | Android | 7.1.1 | All | All | All | |
| Operating System | Android | 7.1.2 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Google Inc. | Android | affected 5.0.2 | Not specified |
| CNA | Google Inc. | Android | affected 5.1.1 | Not specified |
| CNA | Google Inc. | Android | affected 6.0 | Not specified |
| CNA | Google Inc. | Android | affected 6.0.1 | Not specified |
| CNA | Google Inc. | Android | affected 7.0 | Not specified |
| CNA | Google Inc. | Android | affected 7.1.1 | Not specified |
| CNA | Google Inc. | Android | affected 7.1.2 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Google Android Mediaserver CVE-2017-0589 Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Android Security Bulletin—May 2017 | Android Open Source Project | af854a3a-2127-422b-91ae-364da2661108 | source.android.com | Patch, Vendor Advisory |
| bcfc7124f6ef9f1ec128fb2e90de774a5b33d199 - platform/external/libhevc - Git at Google | af854a3a-2127-422b-91ae-364da2661108 | android.googlesource.com | Issue Tracking, Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.