PT-2018-19009 · Google · Android

Published

2018-11-06

·

Updated

2019-10-03

·

CVE-2018-9444

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Android versions 6.0 through 7.1.2
Description The issue is related to a possible resource exhaustion due to an infinite loop in the ih264d video decode function of ih264d api.c. This could lead to a remote temporary device denial of service, resulting in a device hang or reboot, with no additional execution privileges needed. User interaction is required for exploitation.
Recommendations For Android versions 6.0 through 7.1.2, update to a version that contains a fix for this issue to prevent potential remote temporary device denial of service.

Fix

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-9444

Affected Products

Android