PT-2018-6654 · Linux · Linux Kernel

Publicado

2018-06-12

·

Atualizado

2018-08-01

·

CVE-2017-18070

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Linux Kernel (affected versions not specified)
Description: The issue arises in the wma ndp end response event handler() function, where the len end rsp variable, a uint32, can be overflowed if the value of the variable event->num ndp end rsp per ndi list is very large. This overflow can lead to a heap overwrite of the end rsp heap object. The problem affects all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) that use the Linux Kernel.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-18070

Produtos afetados

Linux Kernel