PT-2018-1350 · Qualcomm+1 · Libgralloc+1

Published

2018-05-05

·

Updated

2019-10-03

·

CVE-2017-18154

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android (affected versions not specified)
Description The issue is related to a crafted binder request that can cause an arbitrary unmap in MediaServer, potentially affecting all Android releases from CAF. It is also described as a vulnerability in the Qualcomm Libgralloc component of the MediaServer in the Android operating system, which is associated with a pointer offset beyond the bounds of allocated memory. This could allow an attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00893
CVE-2017-18154

Affected Products

Android
Libgralloc