PT-2017-11714 · Qualcomm+2 · Qrd Android+2
Publicado
2017-10-10
·
Atualizado
2017-10-19
·
CVE-2017-11051
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Android for MSM (affected versions not specified)
Firefox OS for MSM (affected versions not specified)
QRD Android (affected versions not specified)
Description
The issue allows for information disclosure due to the
hb params buffer not being initialized to zero in the wlan hdd cfg80211 testmode function.Recommendations
For Android for MSM, consider restricting access to the
wlan hdd cfg80211 testmode function until a patch is available.
For Firefox OS for MSM, avoid using the wlan hdd cfg80211 testmode function in sensitive operations until the issue is resolved.
For QRD Android, as a temporary workaround, consider disabling the wlan hdd cfg80211 testmode function until a fix is provided.Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Android
Firefox Os
Qrd Android