CVE-2017-0879
CRITICALAndroid 7.0 7.1.1 7.1.2 8.0 - Information Disclosure in Media Framework
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-0879. PoCs published by codecat007.
AI-analyzed exploit summary This repository contains a detailed AddressSanitizer (ASan) output demonstrating a global-buffer-overflow vulnerability in the Android Stagefright library (CVE-2017-0879). The crash occurs in the H.263 decoder, specifically in the `PV_VlcDecMCBPC_com_inter_H263` function, due to an out-of-bounds read.
Description
An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-65025028.
Exploits (1)
This repository contains a detailed AddressSanitizer (ASan) output demonstrating a global-buffer-overflow vulnerability in the Android Stagefright library (CVE-2017-0879). The crash occurs in the H.263 decoder, specifically in the `PV_VlcDecMCBPC_com_inter_H263` function, due to an out-of-bounds read.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H