CVE-2018-9545Out-of-bounds Write in INC Android

Severity
7.8HIGHNVD
EPSS
0.0%
top 94.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 14
Latest updateMay 14

Description

In BTA_HdRegisterApp of bta_hd_api.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-113111784

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5google_inc/androidAndroid-9

Patches

🔴Vulnerability Details

2
GHSA
GHSA-v87m-9fvr-2rrf: In BTA_HdRegisterApp of bta_hd_api2022-05-14
CVEList
CVE-2018-9545: In BTA_HdRegisterApp of bta_hd_api2018-11-14

📋Vendor Advisories

1
Android
CVE-2018-9545: Android Security Bulletin 2018-11-01 CVE: CVE-2018-9545 Severity: HIGH Type: ID Affected AOSP versions: 9 References: A-1131117842018-11-01
CVE-2018-9545 — Out-of-bounds Write in INC Android | cvebase