SB2018011321 - Input validation error in Google, Google Android
Published: January 13, 2018 Updated: August 8, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2017-13214)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
In the hardware HEVC decoder, some media files could cause a page fault. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-38495900.
Remediation
Install update from vendor's website.