VULNERABILITY INTELLIGENCE
CVE-2017-13232
CVSS score7.5 HIGH
EPSS probability0.82%
CISA KEVNot currently listed
Published2018-02-12
Last modified2026-06-17
CVSS vectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Description
In audioserver, there is an out-of-bounds write due to a log statement using %s with an array that may not be NULL terminated. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68953950.
Weakness classification
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-787: Out-of-bounds Write
Primary references
- security@android.com — Third Party Advisory, VDB Entry
- security@android.com — Vendor Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Third Party Advisory, VDB Entry
- af854a3a-2127-422b-91ae-364da2661108 — Vendor Advisory