CVE-2018-9472: Integer Overflow
Published Sep 4, 2018
·Updated
In xmlMemStrdupLoc of xmlmemory.c, there is a possible out-of-bounds write due to an integer overflow. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation.
Affected Software
6 affected components
Google Android
Google Android=7.0
Google Android=7.1.1
Google Android=7.1.2
Google Android=8.0
Google Android=8.1
Remediation
Patch Available
Event History
Sep 4, 2018
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Nov 20, 2024
CVE Published
via MITRE·05:24 PM
Data Sourced
via MITRE·05:24 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-9472?
CVE-2018-9472 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2018-9472?
To fix CVE-2018-9472, update your affected Android devices to a patched version provided by Google.
3
Which versions of Android are affected by CVE-2018-9472?
CVE-2018-9472 affects Android versions 7.0, 7.1.1, 7.1.2, 8.0, and 8.1.
4
What are the potential consequences of CVE-2018-9472?
The potential consequences of CVE-2018-9472 include remote code execution in an unprivileged process.
5
Is user interaction required to exploit CVE-2018-9472?
Yes, user interaction is needed for the exploitation of CVE-2018-9472.