First published: Mon Mar 06 2017(Updated: )
An information disclosure vulnerability in the Qualcomm bootloader could help to enable a local malicious application to to execute arbitrary code within the context of the bootloader. This issue is rated as High because it is a general bypass for a bootloader level defense in depth or exploit mitigation technology. Product: Android. Versions: Kernel-3.18. Android ID: A-32370952. References: QC-CR#1082755.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Linux kernel | =3.18 |
https://source.codeaurora.org/quic/la/kernel/lk/commit/?id=2c00928b4884fdb0b1661bcc530d7e68c9561a2f
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-0455 is rated as High due to its potential to allow local malicious applications to execute arbitrary code within the Qualcomm bootloader.
To fix CVE-2017-0455, update your Android device or Linux kernel to the latest security patches provided by the vendors.
CVE-2017-0455 affects Android devices using Qualcomm bootloaders and Linux kernel version 3.18.
The risks of CVE-2017-0455 include potential unauthorized access and execution of arbitrary code at the bootloader level.
No, CVE-2017-0455 primarily requires local access to exploit the vulnerability.