CVE-2017-0455: Infoleak
An information disclosure vulnerability in the Qualcomm bootloader could help to enable a local malicious application to to execute arbitrary code within the context of the bootloader. This issue is rated as High because it is a general bypass for a bootloader level defense in depth or exploit mitigation technology. Product: Android. Versions: Kernel-3.18. Android ID: A-32370952. References: QC-CR#1082755.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-0455?
CVE-2017-0455 is rated as High due to its potential to allow local malicious applications to execute arbitrary code within the Qualcomm bootloader.
How do I fix CVE-2017-0455?
To fix CVE-2017-0455, update your Android device or Linux kernel to the latest security patches provided by the vendors.
What software is affected by CVE-2017-0455?
CVE-2017-0455 affects Android devices using Qualcomm bootloaders and Linux kernel version 3.18.
What are the risks of CVE-2017-0455?
The risks of CVE-2017-0455 include potential unauthorized access and execution of arbitrary code at the bootloader level.
Can CVE-2017-0455 be exploited remotely?
No, CVE-2017-0455 primarily requires local access to exploit the vulnerability.