Learn about CVE-2017-0401 affecting Android versions 5.0.2 to 7.1. Discover the impact, technical details, and mitigation steps for this information disclosure vulnerability.
Android versions 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, and 7.1 are affected by an information disclosure vulnerability in the Qualcomm audio post processor.
Understanding CVE-2017-0401
A vulnerability in the libeffects component of the Qualcomm audio post processor could allow a nearby malicious application to access data beyond its permissions, impacting Android versions 5.0.2 to 7.1.
What is CVE-2017-0401?
The vulnerability is related to revealing information in the lvm/wrapper/Bundle/EffectBundle.cpp file within the libeffects component.
It has a Moderate severity rating due to the potential unauthorized access to sensitive data.
The Impact of CVE-2017-0401
The vulnerability could enable a local malicious application to access data outside its permission levels.
Affected versions include Android 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, and 7.1.
Technical Details of CVE-2017-0401
The following technical details provide insight into the vulnerability.
Vulnerability Description
The vulnerability exists in the lvm/wrapper/Bundle/EffectBundle.cpp file within the libeffects component.
It allows nearby malicious applications to access data beyond their designated permissions.