PT-2012-4173 · Google · Bionic

Xi Wang

·

Published

2012-07-25

·

Updated

2012-08-24

·

CVE-2012-2674

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Bionic (libc) for Android (affected versions not specified)
Description The issue is related to multiple integer overflows in certain functions within Bionic (libc) for Android. Specifically, the chk malloc, leak malloc, and leak memalign functions in libc/bionic/malloc debug leak.c are affected when libc.debug.malloc is set. This makes it easier for attackers to perform memory-related attacks, such as buffer overflows, by providing a large size value, which results in less memory being allocated than expected.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-2674

Affected Products

Bionic