CVE-2018-9440 — Uncontrolled Resource Consumption in Google Android
4 documents4 sources
Severity
6.5MEDIUMNVD
EPSS
0.2%
top 63.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 19
Latest updateNov 20
Description
In parse of M3UParser.cpp there is a possible resource exhaustion due to improper input validation. This could lead to denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6
Affected Packages3 packages
🔴Vulnerability Details
1📋Vendor Advisories
1Android▶
CVE-2018-9440: Android Security Bulletin 2018-09-01
CVE: CVE-2018-9440
Severity: MEDIUM
Type: DoS
Affected AOSP versions: 7↗2018-09-01
📄Research Papers
1arXiv▶
Hey Google, What Exactly Do Your Security Patches Tell Us? A Large-Scale Empirical Study on Android Patched Vulnerabilities↗2019-05-22