PT-2018-4541 · Google · Android
Published
2018-04-18
·
Updated
2018-05-09
·
CVE-2015-9208
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Android versions prior to 2018-04-05
Description
The issue arises from the function
tzbsp pil verify sig() not strictly checking if the pointer to ELF and program headers and hash segment is within secure memory. It only verifies that the address is not in non-secure memory, which can lead to a situation where an address range overlapping both secure and non-secure regions could be considered valid, even though it could be modified by the non-secure side.Recommendations
For Android versions prior to 2018-04-05, update to a version with a security patch level of 2018-04-05 or later to resolve the issue.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android