CVE-2017-13194Improper Input Validation in INC Android

Severity
7.5HIGHNVD
EPSS
1.3%
top 20.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 12
Latest updateMay 13

Description

A vulnerability in the Android media framework (libvpx) related to odd frame width. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-64710201.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDgoogle/android8 versions+7
CVEListV5google_inc/android5 versions+4
Debianwebmproject/libvpx< 1.7.0-2+3

Also affects: Debian Linux 7.0, 8.0, 9.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-9g26-5wqj-4px2: A vulnerability in the Android media framework (libvpx) related to odd frame width2022-05-13
OSV
CVE-2017-13194: A vulnerability in the Android media framework (libvpx) related to odd frame width2018-01-12
CVEList
CVE-2017-13194: A vulnerability in the Android media framework (libvpx) related to odd frame width2018-01-12

📋Vendor Advisories

4
Ubuntu
libvpx vulnerabilities2020-07-15
Ubuntu
libvpx vulnerabilities2019-11-25
Red Hat
libvpx: denial of service (DoS) in vpx/src/vpx_image.c file2018-01-02
Debian
CVE-2017-13194: libvpx - A vulnerability in the Android media framework (libvpx) related to odd frame wid...2017

💬Community

2
Bugzilla
CVE-2017-13194 libvpx: denial of service (DoS) in vpx/src/vpx_image.c file [fedora-all]2018-01-16
Bugzilla
CVE-2017-13194 libvpx: denial of service (DoS) in vpx/src/vpx_image.c file2018-01-16
CVE-2017-13194 — Improper Input Validation | cvebase