CVE-2018-9508Out-of-bounds Read in INC Android

CWE-125Out-of-bounds Read4 documents4 sources
Severity
6.5MEDIUMNVD
EPSS
0.3%
top 50.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 2
Latest updateMay 14

Description

In smp_process_keypress_notification of smp_act.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-111936834

CVSS vector

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDgoogle/android5 versions+4
CVEListV5google_inc/androidAndroid-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4p65-8fmp-gmqv: In smp_process_keypress_notification of smp_act2022-05-14
CVEList
CVE-2018-9508: In smp_process_keypress_notification of smp_act2018-10-02

📋Vendor Advisories

1
Android
CVE-2018-9508: Android Security Bulletin 2018-10-01 CVE: CVE-2018-9508 Severity: HIGH Type: ID Affected AOSP versions: 72018-10-01
CVE-2018-9508 — Out-of-bounds Read in INC Android | cvebase