CVE-2018-9455Out-of-bounds Read in INC Android

CWE-125Out-of-bounds Read4 documents4 sources
Severity
7.5HIGHNVD
EPSS
0.6%
top 30.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 6
Latest updateMay 14

Description

In sdpu_extract_attr_seq of sdp_utils.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-78136677.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDgoogle/android7 versions+6
CVEListV5google_inc/androidAndroid-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4pf4-6f6p-fjw5: In sdpu_extract_attr_seq of sdp_utils2022-05-14
CVEList
CVE-2018-9455: In sdpu_extract_attr_seq of sdp_utils2018-11-06

📋Vendor Advisories

1
Android
CVE-2018-9455: Android Security Bulletin 2018-08-01 CVE: CVE-2018-9455 Severity: HIGH Type: DoS Affected AOSP versions: 62018-08-01
CVE-2018-9455 — Out-of-bounds Read in INC Android | cvebase