PT-2018-1958 · Google · Android

Published

2018-09-19

·

Updated

2020-08-24

·

CVE-2018-9565

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android version 9
Description The issue is caused by an integer overflow in the readBytes function of xltdecwbxml.c, which can lead to an out of bounds read. This could allow an attacker to disclose protected information using a specially crafted request. No additional execution privileges are needed, and user interaction is not required for exploitation.
Recommendations For Android version 9, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Out of bounds Read

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-01565
CVE-2018-9565

Affected Products

Android