cbcvebase.
CVE-2017-13284
published 2018-04-04

CVE-2017-13284: In config_set_string of config.cc, it is possible to pair a second BT keyboard without user approval due to improper input validation. This could lead to…

critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
In config_set_string of config.cc, it is possible to pair a second BT keyboard without user approval due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-70808273.

Affected

15 ranges
VendorProductVersion rangeFixed in
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
google_incandroid
google_incandroid
google_incandroid
google_incandroid
google_incandroid
google_incandroid
google_incandroid