PT-2018-5726 · Mozilla+2 · Firefox Os+2
Published
2018-01-10
·
Updated
2018-01-26
·
CVE-2017-14869
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Android for MSM (affected versions not specified)
Firefox OS for MSM (affected versions not specified)
QRD Android (affected versions not specified)
Description:
The issue occurs during the update of the FOTA partition in the mentioned operating systems, where uninitialized data can be pushed to storage.
Recommendations:
For Android for MSM, update the system to ensure proper initialization of data before pushing it to storage.
For Firefox OS for MSM, ensure that all data is properly initialized before the FOTA partition update.
For QRD Android, modify the FOTA partition update process to prevent uninitialized data from being pushed to storage.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android
Firefox Os
Qrd Android