CVE-2014-9795: Integer Overflow
app/aboot/aboot.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 devices does not properly check for an integer overflow, which allows attackers to bypass intended access restrictions via crafted start and size values, aka Android internal bug 28820720 and Qualcomm internal bug CR681957, a related issue to CVE-2014-4325.
Affected Software
Event History
Frequently Asked Questions
Which devices are identified as affected?
The issue is identified in Qualcomm components on Nexus 5 devices running Android versions before 2016-07-05.
What does exploitation require?
The CVSS vector indicates local attack access and user interaction, with no privileges required. An attacker uses crafted start and size values to trigger an integer-overflow condition and bypass intended access restrictions.
What is the impact of a successful exploit?
Successful exploitation can bypass intended access restrictions. The supplied CVSS vector rates confidentiality, integrity, and availability impact as high.