CVE-2018-9565: Integer Overflow
In readBytes of xltdecwbxml.c, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-16680558.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker can exploit it without authentication, additional execution privileges, or user interaction.
What is the security impact?
Successful exploitation may disclose information because an integer overflow can cause an out-of-bounds read in readBytes of xltdecwbxml.c. The provided CVSS vector indicates confidentiality impact only, with no stated integrity or availability impact.
Which Android versions are identified as affected?
The provided data identifies Android 9 as affected.
How can I identify this issue in Android security tracking?
The Android issue identifier is A-16680558. The issue is also associated with the December 1, 2018 Android security bulletin.