First published: Mon Aug 06 2018(Updated: )
In ih264d_video_decode of ih264d_api.c there is a possible resource exhaustion due to an infinite loop. This could lead to remote temporary device denial of service (remote hang or reboot) with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android ID: A-63521984.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =6.0 | |
Google Android | =6.0.1 | |
Google Android | =7.0 | |
Google Android | =7.1.1 | |
Google Android | =7.1.2 | |
Google Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-9444 has a medium severity rating due to the potential for resource exhaustion leading to temporary device denial of service.
To fix CVE-2018-9444, update your Android device to the latest available version that addresses this vulnerability.
CVE-2018-9444 affects Android versions 6.0, 6.0.1, 7.0, 7.1.1, and 7.1.2.
Yes, user interaction is required for the exploitation of CVE-2018-9444.
CVE-2018-9444 can cause a remote temporary device hang or reboot, leading to denial of service.