CVE-2017-9720: High severity Google Android vulnerability
Published Sep 5, 2017
·Updated
In all Qualcomm products with Android releases from CAF using the Linux kernel, due to an off-by-one error in a camera driver, an out-of-bounds read/write can occur.
Affected Software
2 affected components
Google Android<=8.0
Google Android
Event History
Sep 5, 2017
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Sep 21, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What level of access is required to exploit this issue?
The CVSS vector identifies this as a local attack with low complexity. It does not require privileges, but it does require user interaction.
2
What is the potential security impact of successful exploitation?
The vulnerability can cause an out-of-bounds read or write in a camera driver. It is rated High for confidentiality, integrity, and availability impact.