CVE-2017-13318 Details
Description
In HeifDataSource::readAt of HeifDecoderImpl.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
A vulnerability allowing out-of-bounds read due to integer overflow has been identified in the HEIF decoder component of Google Android. This issue could lead to remote information disclosure without requiring additional execution privileges. Exploitation of this vulnerability does require user interaction.
Users can update their devices to the May 2018 security patch level to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://source.android.com/security/bulletin/pixel/2018-05-01 | [email protected] | PatchVendor Advisory |
Weakness Enumeration
Affected Products
| Product | Versions |
|---|---|
| google android | 8.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 10, 2025 | Initial Analysis | [email protected] |
| Jan 28, 2025 | CVE Modified | CISA-ADP |
| Jan 28, 2025 | New CVE Received | [email protected] |