PT-2017-3613 · Google · Android
Publicado
2017-09-27
·
Atualizado
2018-04-06
·
CVE-2017-18064
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Android versions (affected versions not specified)
Description:
The issue is related to improper input validation for
p2p noa info in the wma send bcn buf ll() function, which can lead to a potential buffer overflow. This is due to insufficient input validation received from firmware. The vulnerability in the wma send bcn buf ll() function of the WLAN component in the Android operating system from the CAF repository can allow an attacker to execute arbitrary code in the context of a privileged process using a specially crafted file.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Android