In store_cmd of ftm4_pdc.c, there is a possible out of bounds write due to
an incorrect bounds check. This could lead to local escalation of privilege
with System execution privileges needed. User interaction is not needed for
exploitation.
References
Link | Resource |
---|---|
https://source.android.com/security/bulletin/pixel/2018-08-01 | Vendor Advisory |
Configurations
History
19 Dec 2024, 17:05
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.7 |
References | () https://source.android.com/security/bulletin/pixel/2018-08-01 - Vendor Advisory | |
First Time |
Google
Google android |
|
CPE | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* | |
Summary | (es) En store_cmd de ftm4_pdc.c, existe una posible escritura fuera de los límites debido a una verificación de los límites incorrecta. Esto podría provocar una escalada local de privilegios, siendo necesarios los permisos de ejecución de System. No se necesita la interacción del usuario para la explotación. |
05 Dec 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
Summary |
|
|
CWE | CWE-787 |
05 Dec 2024, 00:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-12-05 00:15
Updated : 2024-12-19 17:05
NVD link : CVE-2018-9462
Mitre link : CVE-2018-9462
CVE.ORG link : CVE-2018-9462
JSON object : View
Products Affected
- android
CWE
CWE-787
Out-of-bounds Write