Infinite Loop and Resource Exhaustion in ESQueue's dequeueAccessUnitMPEG4Video
CVE-2017-13313

6.5MEDIUM

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
15 November 2024

What is CVE-2017-13313?

The vulnerability in the Android Media Framework is linked to the ElementaryStreamQueue::dequeueAccessUnitMPEG4Video function within ESQueue.cpp. It can trigger an infinite loop resulting in resource exhaustion. This condition can lead to a denial of service where the affected service becomes unresponsive. Exploitation requires user interaction, making it crucial for users to be cautious while processing MPEG4 video content. Adequate measures should be taken to ensure system updates and patches are applied to protect against this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Android 6

Android 6.0.1

Android 7

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.