CVE-2017-0718
HIGHAndroid 6.0 6.0.1 7.0 7.1.1 7.1.2 - Remote Code Execution in MPEG2 Decoder
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-0718. PoCs published by codecat007.
AI-analyzed exploit summary The repository contains a detailed AddressSanitizer (ASan) log demonstrating a double-free vulnerability in the Android SoftMPEG2 decoder (CVE-2017-0718). The log shows the crash occurring in `deInitDecoder()` and the destructor of `SoftMPEG2`, indicating a memory management issue.
Description
A remote code execution vulnerability in the Android media framework (mpeg2 decoder). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37273547.
Exploits (1)
The repository contains a detailed AddressSanitizer (ASan) log demonstrating a double-free vulnerability in the Android SoftMPEG2 decoder (CVE-2017-0718). The log shows the crash occurring in `deInitDecoder()` and the destructor of `SoftMPEG2`, indicating a memory management issue.
References (2)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H