PT-2018-5743 · Mozilla+2 · Firefox Os+2
Published
2018-03-30
·
Updated
2018-04-23
·
CVE-2017-14891
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Android for MSM (affected versions not specified)
Firefox OS for MSM (affected versions not specified)
QRD Android (affected versions not specified)
Description:
The issue is related to the KGSL driver function
gpuobj map useraddr(), where the contents of the stack can be leaked due to an uninitialized variable. This could potentially expose sensitive information.Recommendations:
For Android for MSM, update to a version released after 2017-10-12.
For Firefox OS for MSM, update to a version released after 2017-10-12.
For QRD Android, update to a version released after 2017-10-12.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android
Firefox Os
Qrd Android