CVE-2018-9542: High severity Google Android vulnerability
In avrcparsvendorrsp of avrcparsct.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-111896861
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The issue is remotely exploitable over the network with low attack complexity. It requires no privileges and no user interaction.
What is the security impact if exploitation succeeds?
Successful exploitation can disclose information through an out-of-bounds read. The supplied CVSS vector indicates high confidentiality impact, with no integrity or availability impact.
Which Android versions are affected?
The affected versions listed are Android 7.0, 7.1.1, 7.1.2, 8.0, 8.1, and 9.
Is a fix available?
Yes. A patch is available; the issue is tracked by Android as A-111896861 and is covered by the November 1, 2018 Android security bulletin.