Buffer overflow in Google Android - CVE-2017-18064

 

Buffer overflow in Google Android - CVE-2017-18064

Published: March 15, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU37426
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-18064
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to execute arbitrary code.

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for p2p_noa_info in wma_send_bcn_buf_ll() which is received from firmware leads to potential buffer overflow.


Affected software

Google Android

How to mitigate CVE-2017-18064

Install update from vendor's website.


External References

Related Security Bulletins