PT-2018-5511 · Google · Android Kernel

Publicado

2018-01-12

·

Atualizado

2018-01-30

·

CVE-2017-13217

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Android kernel
Description: The issue is related to an out-of-bounds write in the bootloader due to reading a string without verifying that it's null-terminated. This could lead to a secure boot bypass and a local elevation of privilege, enabling code execution as a privileged process with no additional execution privileges needed. User interaction is not required for exploitation.
Recommendations: For Android kernel, apply the necessary patch to fix the out-of-bounds write issue in the bootloader to prevent secure boot bypass and local elevation of privilege.

Correção

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-13217

Produtos afetados

Android Kernel