PT-2018-1958 · Google · Android

Publicado

2018-09-19

·

Atualizado

2020-08-24

·

CVE-2018-9565

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android version 9
Description The issue is caused by an integer overflow in the readBytes function of xltdecwbxml.c, which can lead to an out of bounds read. This could allow an attacker to disclose protected information using a specially crafted request. No additional execution privileges are needed, and user interaction is not required for exploitation.
Recommendations For Android version 9, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Out of bounds Read

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-01565
CVE-2018-9565

Produtos afetados

Android