PT-2017-3613 · Google · Android

Published

2017-09-27

·

Updated

2018-04-06

·

CVE-2017-18064

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Android versions (affected versions not specified)
Description: The issue is related to improper input validation for p2p noa info in the wma send bcn buf ll() function, which can lead to a potential buffer overflow. This is due to insufficient input validation received from firmware. The vulnerability in the wma send bcn buf ll() function of the WLAN component in the Android operating system from the CAF repository can allow an attacker to execute arbitrary code in the context of a privileged process using a specially crafted file.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00596
CVE-2017-18064

Affected Products

Android