CVE-2018-9507Out-of-bounds Read in INC Android

CWE-125Out-of-bounds Read4 documents4 sources
Severity
6.5MEDIUMNVD
EPSS
0.3%
top 47.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 2
Latest updateMay 14

Description

In bta_av_proc_meta_cmd of bta_av_act.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-111893951

CVSS vector

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDgoogle/android6 versions+5
CVEListV5google_inc/androidAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-jr2g-frfq-v8g3: In bta_av_proc_meta_cmd of bta_av_act2022-05-14
CVEList
CVE-2018-9507: In bta_av_proc_meta_cmd of bta_av_act2018-10-02

📋Vendor Advisories

1
Android
CVE-2018-9507: Android Security Bulletin 2018-10-01 CVE: CVE-2018-9507 Severity: HIGH Type: ID Affected AOSP versions: 72018-10-01
CVE-2018-9507 — Out-of-bounds Read in INC Android | cvebase