CVE-2017-18292: Input Validation
Secure app running in non secure space can restart TZ by calling Widevine app API repeatedly in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in versions MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 810, SD 820, SD 820A.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-18292?
CVE-2017-18292 is a vulnerability in Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear that allows a secure app running in a non-secure space to restart TZ by calling Widevine app API repeatedly.
How severe is CVE-2017-18292?
CVE-2017-18292 has a severity rating of 5.5, which is considered high.
Which software versions are affected by CVE-2017-18292?
CVE-2017-18292 affects Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear in versions MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800.
How can I fix CVE-2017-18292?
To fix CVE-2017-18292, it is recommended to apply the patches provided by the vendor.
Where can I find more information about CVE-2017-18292?
More information about CVE-2017-18292 can be found on the official Android security bulletin for August 2018.