PT-2017-3613 · Google · Android
Published
2017-09-27
·
Updated
2018-04-06
·
CVE-2017-18064
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Android versions (affected versions not specified)
Description:
The issue is related to improper input validation for
p2p noa info in the wma send bcn buf ll() function, which can lead to a potential buffer overflow. This is due to insufficient input validation received from firmware. The vulnerability in the wma send bcn buf ll() function of the WLAN component in the Android operating system from the CAF repository can allow an attacker to execute arbitrary code in the context of a privileged process using a specially crafted file.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Android