CVE-2017-13259Out-of-bounds Read in INC Android

CWE-125Out-of-bounds Read4 documents4 sources
Severity
7.5HIGHNVD
EPSS
0.8%
top 25.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 4
Latest updateMay 14

Description

In functionality implemented in sdp_discovery.cc, there are possible out of bounds reads due to missing bounds checks. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68161546.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDgoogle/android8 versions+7
CVEListV5google_inc/android8 versions+7

🔴Vulnerability Details

2
GHSA
GHSA-85wx-7wq7-fx45: In functionality implemented in sdp_discovery2022-05-14
CVEList
CVE-2017-13259: In functionality implemented in sdp_discovery2018-04-04

📋Vendor Advisories

1
Android
CVE-2017-13259: Android Security Bulletin 2018-03-01 CVE: CVE-2017-13259 Severity: HIGH Type: ID Affected AOSP versions: 52018-03-01
CVE-2017-13259 — Out-of-bounds Read in INC Android | cvebase