PT-2018-1350 · Qualcomm+1 · Libgralloc+1

Publicado

2018-05-05

·

Atualizado

2019-10-03

·

CVE-2017-18154

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android (affected versions not specified)
Description The issue is related to a crafted binder request that can cause an arbitrary unmap in MediaServer, potentially affecting all Android releases from CAF. It is also described as a vulnerability in the Qualcomm Libgralloc component of the MediaServer in the Android operating system, which is associated with a pointer offset beyond the bounds of allocated memory. This could allow an attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-00893
CVE-2017-18154

Produtos afetados

Android
Libgralloc