CVE-2017-11000: Buffer Overflow
Published Sep 5, 2017
·Updated
In all Qualcomm products with Android releases from CAF using the Linux kernel, in an ISP Camera kernel driver function, an incorrect bounds check may potentially lead to an out-of-bounds write.
Affected Software
2 affected components
Google Android<=8.0
Google Android
Event History
Sep 5, 2017
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Sep 21, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What level of attacker access is required?
The CVSS vector indicates local access is required, no privileges are required, and user interaction is required. The attack vector is local rather than network-based.
2
Which systems are in scope?
The issue affects Qualcomm products using Android releases from CAF with the Linux kernel, specifically involving an ISP Camera kernel driver function. The listed software is Google Android.
3
What is the potential security impact?
The CVSS vector rates confidentiality, integrity, and availability impact as high. The underlying issue is an out-of-bounds write caused by an incorrect bounds check.