PT-2017-3614 · Google · Android

Publicado

2017-09-27

·

Atualizado

2018-04-06

·

CVE-2017-18063

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Android (affected versions not specified)
Description: The issue is related to the wma nlo match evt handler function in the WLAN component of the Android operating system, which is part of the CAF repository. It involves an out-of-bounds memory access operation. This could allow an attacker to execute arbitrary code in the context of a privileged process using a specially crafted file. The problem arises from improper input validation for the nlo event in the wma nlo match evt handler() function, which receives input from firmware.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-00597
CVE-2017-18063

Produtos afetados

Android