PT-2017-3613 · Google · Android

Publicado

2017-09-27

·

Atualizado

2018-04-06

·

CVE-2017-18064

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Android versions (affected versions not specified)
Description: The issue is related to improper input validation for p2p noa info in the wma send bcn buf ll() function, which can lead to a potential buffer overflow. This is due to insufficient input validation received from firmware. The vulnerability in the wma send bcn buf ll() function of the WLAN component in the Android operating system from the CAF repository can allow an attacker to execute arbitrary code in the context of a privileged process using a specially crafted file.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-00596
CVE-2017-18064

Produtos afetados

Android