A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-38207066.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
google android 7.1.0 |
||
google android 7.1.2 |
||
google android 6.0.1 |
||
google android 6.0 |
||
google android 7.0 |
||
google android 8.0 |
||
google android 7.1.1 |
There's a nasty bug in media file handling – deja vu, right?
Another month, another round of Android patches – although October's batch is pleasantly small compared to other recent releases. Of the 14 CVE flaws released, six cover Android's troubled media processing and playback engine. This means miscreants can fling malicious files at devices to potentially hijack them. The privilege escalation bugs can be used by dodgy apps to gain control of handsets and tablets. There's also a remote-code execution flaw in the Dnsmasq tool used by Android. Details ...