PT-2018-5726 · Mozilla+2 · Firefox Os+2

Published

2018-01-10

·

Updated

2018-01-26

·

CVE-2017-14869

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Android for MSM (affected versions not specified) Firefox OS for MSM (affected versions not specified) QRD Android (affected versions not specified)
Description: The issue occurs during the update of the FOTA partition in the mentioned operating systems, where uninitialized data can be pushed to storage.
Recommendations: For Android for MSM, update the system to ensure proper initialization of data before pushing it to storage. For Firefox OS for MSM, ensure that all data is properly initialized before the FOTA partition update. For QRD Android, modify the FOTA partition update process to prevent uninitialized data from being pushed to storage.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-14869

Affected Products

Android
Firefox Os
Qrd Android