CVE-2018-3898: Buffer Overflow
An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted QR Code can cause a buffer overflow, resulting in code execution. The transinfo call can overwrite a buffer of size 0x104, which is more than enough to overflow the return address from the ssiddst field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-3898?
CVE-2018-3898 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2018-3898?
To fix CVE-2018-3898, update the Yi Home Camera firmware to the latest version that addresses this vulnerability.
What systems are affected by CVE-2018-3898?
CVE-2018-3898 specifically affects the Yi Home Camera firmware version 1.8.7.0D.
What type of attack is possible with CVE-2018-3898?
CVE-2018-3898 allows an attacker to execute arbitrary code through a specially crafted QR code.
Is there a workaround for CVE-2018-3898 if I cannot update my device?
If you cannot update, avoid scanning unknown QR codes to mitigate the risk associated with CVE-2018-3898.