PT-2017-3657 · Google · Android

Published

2017-12-19

·

Updated

2019-10-03

·

CVE-2018-3594

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Android versions prior to security patch level 2018-04-05
Description: A buffer over-read can occur when parsing a private frame in an ID3 tag, potentially allowing a remote attacker to impact the confidentiality, integrity, and availability of protected information. This issue is related to the Qualcomm Video Services component in the Android operating system and involves an out-of-bounds operation in memory when processing ID3 metadata.
Recommendations: For Android versions prior to security patch level 2018-04-05, update to a version with a security patch level of 2018-04-05 or later to resolve the issue.

Fix

Buffer Overflow

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00846
CVE-2018-3594

Affected Products

Android