CVE-2017-18694: Infoleak
An issue was discovered on Samsung mobile devices with software through 2016-10-25 (Exynos5 chipsets). Attackers can read kernel addresses in the log because an incorrect format specifier is used. The Samsung ID is SVE-2016-7551 (January 2017).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-18694?
CVE-2017-18694 is a vulnerability on Samsung mobile devices with software through 2016-10-25 (Exynos5 chipsets) that allows attackers to read kernel addresses in the log due to an incorrect format specifier.
How severe is CVE-2017-18694?
CVE-2017-18694 has a severity score of 5.3, which is considered medium.
How can I check if I am affected by CVE-2017-18694?
If you are using a Samsung mobile device with software through 2016-10-25 and Exynos5 chipsets, you may be affected by CVE-2017-18694.
What is the official reference for CVE-2017-18694?
The official reference for CVE-2017-18694 is https://security.samsungmobile.com/securityUpdate.smsb.
How do I fix CVE-2017-18694?
To fix CVE-2017-18694, update your Samsung mobile device software to a version released after 2016-10-25.