Information disclosure in Google Android - CVE-2017-13238

 

Information disclosure in Google Android - CVE-2017-13238

Published: February 12, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU37539
CSH Severity: Low
CVSS v4: 4.1 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-13238
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local non-authenticated attacker to gain access to sensitive information.

In XBLRamDump mode, there is a debug feature that can be used to dump memory contents, if an attacker has physical access to the device. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-64610940.


Affected software

Google Android

How to mitigate CVE-2017-13238

Install update from vendor's website.


External References

Related Security Bulletins