CVE-2017-0793: Infoleak
Published Sep 5, 2017
·Updated
A information disclosure vulnerability in the N/A memory subsystem. Product: Android. Versions: Android kernel. Android ID: A-35764946.
Affected Software
2 affected components
Google Android<=8.0
Google Android
Event History
Sep 5, 2017
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Sep 8, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates local access is required, but no privileges are needed. Exploitation also requires user interaction.
2
What is the security impact if exploitation succeeds?
Successful exploitation can disclose highly sensitive information. The provided CVSS vector does not indicate an integrity or availability impact.
3
Which component should be checked when triaging affected devices?
Check the Android kernel and the device's applied Android security updates. The issue is identified as Android ID A-35764946 and appears in the September 1, 2017 Android security bulletin.