PT-2019-8865 · Mozilla+2 · Firefox Os+2
Published
2019-02-11
·
Updated
2020-08-24
·
CVE-2018-12011
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Android for MSM (affected versions not specified)
Firefox OS for MSM (affected versions not specified)
QRD Android (affected versions not specified)
Description
The issue is related to uninitialized data for socket address, which leads to information exposure. This affects Android releases using the Linux kernel.
Recommendations
For Android for MSM, update to a version that includes the necessary fixes for the uninitialized socket address issue.
For Firefox OS for MSM, apply the recommended configuration changes to mitigate the information exposure risk.
For QRD Android, restrict access to sensitive data until a patched version is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Use of Uninitialized Resource
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android
Firefox Os
Linux Kernel