cbcvebase.
CVE-2017-0381
published 2017-01-12

CVE-2017-0381: An information disclosure vulnerability in silk/NLSF_stabilize.c in libopus in Mediaserver could enable a local malicious application to access data outside of…

PriorityP431high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
0.15%
35.6th percentile
An information disclosure vulnerability in silk/NLSF_stabilize.c in libopus in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-31607432.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
appleios
applemacos_high_sierra
appletvos
applewatchos_4
debianopus< opus 1.2~alpha2-1 (bookworm)opus 1.2~alpha2-1 (bookworm)
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
google_incandroid
google_incandroid
google_incandroid
google_incandroid
google_incandroid
google_incandroid
wikepageopus>= 0 < 1.2~alpha2-11.2~alpha2-1
wikepageopus>= 0 < 1.2~alpha2-11.2~alpha2-1
wikepageopus>= 0 < 1.2~alpha2-11.2~alpha2-1

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH