An information disclosure vulnerability in silk/NLSF_stabilize.c in libopus in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-31607432.
The MITRE CVE dictionary describes this issue as:
Find out more about CVE-2017-0381 from the MITRE CVE dictionary dictionary and NIST NVD.
NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.
CVSS3 Base Score | 3.1 |
---|---|
CVSS3 Base Metrics | CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L |
Attack Vector | Network |
Attack Complexity | High |
Privileges Required | None |
User Interaction | Required |
Scope | Unchanged |
Confidentiality | None |
Integrity Impact | None |
Availability Impact | Low |
Platform | Package | State |
---|---|---|
Red Hat Enterprise Linux 7 | firefox | Will not fix |
Red Hat Enterprise Linux 7 | opus | Will not fix |
Red Hat Enterprise Linux 7 | thunderbird | Will not fix |
Red Hat Enterprise Linux 6 | firefox | Will not fix |
Red Hat Enterprise Linux 6 | thunderbird | Will not fix |
Red Hat Enterprise Linux 5 | thunderbird | Will not fix |
Red Hat Enterprise Linux 5 | firefox | Will not fix |