PT-2018-1618 · Google · Android
Published
2018-06-25
·
Updated
2018-11-20
·
CVE-2018-9497
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Android versions 7.0 through 9.0
Description
The issue is related to the
impeg2 fmt conv yuv420p to yuv420sp uv av8 function in the Media framework component of the Android operating system. It involves an out-of-bounds write due to a missing bounds check, which could lead to remote code execution. User interaction is required for exploitation.Recommendations
For Android versions 7.0 through 9.0, consider restricting access to the
impeg2 fmt conv yuv420p to yuv420sp uv av8 function until a patch is available. As a temporary workaround, disabling the impeg2 fmt conv yuv420p to yuv420sp uv av8 function may help minimize the risk of exploitation.Fix
Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Android