7.5
CVSSv3

CVE-2017-13194

Published: 12/01/2018 Updated: 24/07/2020
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

It exists that libvpx did not properly handle certain malformed WebM media files. If an application using libvpx opened a specially crafted WebM file, a remote attacker could cause a denial of service, or possibly execute arbitrary code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google android 6.0.1

google android 5.1.1

google android 7.1.2

google android 8.0

google android 8.1

google android 7.1.1

google android 6.0

google android 7.0

debian debian linux 7.0

debian debian linux 8.0

debian debian linux 9.0

Vendor Advisories

Several security issues were fixed in libvpx ...
It was discovered that incorrect validation of frame widths in the libvpx multimedia library may result in denial of service and potentially the execution of arbitrary code For the oldstable distribution (jessie), this problem has been fixed in version 130-3+deb8u1 For the stable distribution (stretch), this problem has been fixed in version 1 ...
Denial of service (DoS) in vpx/src/vpx_imagec fileA vulnerability in the Android media framework (libvpx) related to odd frame width (CVE-2017-13194) ...
Denial of service (DoS) in vpx/src/vpx_imagec fileA vulnerability in the Android media framework (libvpx) related to odd frame width(CVE-2017-13194) ...
A vulnerability in the Android media framework (libvpx) related to odd frame width Product: Android Versions: 70, 711, 712, 80, 81 Android ID: A-64710201 ...