CVE-2018-5907: Buffer Overflow
Published Jul 6, 2018
·Updated
Possible buffer overflow in msmadspstreamcallbackput due to lack of input validation of user-provided data that leads to integer overflow in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.
Affected Software
1 affected component
Google Android<=8.1
Event History
Jul 6, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Data Sourced
via NVD·07:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attack vector is local and requires low privileges. No user interaction is required.
2
Which deployments are in scope?
The issue affects Android releases using the CAF Linux kernel, including Android for MSM, Firefox OS for MSM, and QRD Android.
3
What could successful exploitation allow?
Successful exploitation can have high impact on confidentiality, integrity, and availability. The CVSS scope is unchanged, indicating the impact is within the same security authority.