CVE-2017-0855
Last modified
CVE-2017-0855 is a vulnerability of currently unknown severity. In MPEG4Extractor.cpp, there are several places where functions return early without cleaning up internal buffers which could lead to memory leaks. This could lead to remote denial of service of a critical system process with no additional execution privileges needed. EPSS estimates a 1.73% chance of exploitation in the next 30 days.
Description
In MPEG4Extractor.cpp, there are several places where functions return early without cleaning up internal buffers which could lead to memory leaks. This could lead to remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-64452857.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | 5.1.1 | |
| Android | 6.0 | |
| Android | 6.0.1 | |
| Android | 7.0 | |
| Android | 7.1.1 | |
| Android | 7.1.2 | |
| Android | 8.0 |
References
- http://www.securityfocus.com/bid/102414Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040106Third Party Advisory, VDB Entry
- https://source.android.com/security/bulletin/2018-01-01Patch, Vendor Advisory
- http://www.securityfocus.com/bid/102414Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040106Third Party Advisory, VDB Entry
- https://source.android.com/security/bulletin/2018-01-01Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-0855?
How severe is CVE-2017-0855?
How do I fix CVE-2017-0855?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-0849An information disclosure vulnerability in the Android media…
- CVE-2017-0850An information disclosure vulnerability in the Android media…
- CVE-2017-0851An information disclosure vulnerability in the Android media…
- CVE-2017-0852A denial of service vulnerability in the Android media frame…
- CVE-2017-0853An information disclosure vulnerability in the Android media…
- CVE-2017-0854An information disclosure vulnerability in the Android media…
- CVE-2017-0857Another vulnerability in the Android media framework (n/a). …
- CVE-2017-0858Another vulnerability in the Android media framework (n/a). …
- CVE-2017-0859Another vulnerability in the Android media framework (n/a). …
- CVE-2017-0860An elevation of privilege vulnerability in the Android syste…
- CVE-2017-0861Use-after-free vulnerability in the snd_pcm_info function in…
- CVE-2017-0862An elevation of privilege vulnerability in the Upstream kern…
Are you affected by CVE-2017-0855?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
