CVE-2017-11040: Infoleak
Published Sep 5, 2017
·Updated
In all Qualcomm products with Android releases from CAF using the Linux kernel, when reading from sysfs nodes, one can read more information than it is allowed to.
Affected Software
2 affected components
Google Android<=8.0
Google Android
Event History
Sep 5, 2017
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Sep 21, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The CVSS vector indicates local access is required and no privileges are needed. Exploitation also requires user interaction.
2
What is the security impact if exploitation succeeds?
The issue can disclose information through reads from sysfs nodes. The CVSS vector rates confidentiality impact as high, with no integrity or availability impact.
3
Which systems are in scope?
The affected scope is Qualcomm products using Android releases from CAF with the Linux kernel. The listed software is Google Android.