CVE-2017-11001: Infoleak
Published Sep 5, 2017
·Updated
In all Qualcomm products with Android releases from CAF using the Linux kernel, the length of the MAC address is not checked which may cause out of bounds read.
Affected Software
2 affected components
Google Android<=8.0
Google Android
Event History
Sep 5, 2017
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Sep 21, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker needs local access and does not need privileges. Exploitation also requires user interaction.
2
What is the expected security impact if exploitation succeeds?
The issue may allow disclosure of information through an out-of-bounds read. The provided CVSS vector indicates high confidentiality impact, with no integrity or availability impact.
3
Which environments are exposed?
The affected scope is Qualcomm products using Android releases from CAF with the Linux kernel.