CVE-2018-9440: Input Validation
Published Sep 4, 2018
·Updated
In parse of M3UParser.cpp there is a possible resource exhaustion due to improper input validation. This could lead to denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
Affected Software
7 affected components
Google Android
Google Android=7.0
Google Android=7.1.1
Google Android=7.1.2
Google Android=8.0
Google Android=8.1
Google Android=9.0
Event History
Sep 4, 2018
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Nov 19, 2024
CVE Published
via MITRE·10:18 PM
Data Sourced
via MITRE·10:18 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-9440?
CVE-2018-9440 has a severity rating that can lead to denial of service due to resource exhaustion.
2
How do I fix CVE-2018-9440?
To fix CVE-2018-9440, update your Android device to the latest security patch provided by Google.
3
What versions of Android are affected by CVE-2018-9440?
CVE-2018-9440 affects Android versions 7.0, 7.1.1, 7.1.2, 8.0, 8.1, and 9.0.
4
Is user interaction required to exploit CVE-2018-9440?
Yes, user interaction is needed for the exploitation of CVE-2018-9440.
5
What type of vulnerability is CVE-2018-9440?
CVE-2018-9440 is a vulnerability related to improper input validation that can result in resource exhaustion.