PT-2019-8865 · Mozilla+2 · Firefox Os+2

Published

2019-02-11

·

Updated

2020-08-24

·

CVE-2018-12011

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android for MSM (affected versions not specified) Firefox OS for MSM (affected versions not specified) QRD Android (affected versions not specified)
Description The issue is related to uninitialized data for socket address, which leads to information exposure. This affects Android releases using the Linux kernel.
Recommendations For Android for MSM, update to a version that includes the necessary fixes for the uninitialized socket address issue. For Firefox OS for MSM, apply the recommended configuration changes to mitigate the information exposure risk. For QRD Android, restrict access to sensitive data until a patched version is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-12011

Affected Products

Android
Firefox Os
Linux Kernel