VulnerabilityModified
CVE-2017-18281
A bool variable in Video function, which gets typecasted to int before being read could result in an out of bound read access in all Android releases from CAF using the linux kernel
MEDIUM 5.5EPSS 0.17%
Does this matter?
Lower severity and a low EPSS score (0.17%). Track it; it rarely justifies an emergency change on its own.
Description
A bool variable in Video function, which gets typecasted to int before being read could result in an out of bound read access in all Android releases from CAF using the linux kernel
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.17% probability · 7th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- google/android
- Source
- product-security@qualcomm.com
References
- http://www.securitytracker.com/id/1041432Third Party Advisory, VDB Entry
- https://www.codeaurora.org/security-bulletin/2018/10/01/october-2018-code-aurora-security-bulletinPatch, Third Party Advisory
- http://www.securitytracker.com/id/1041432Third Party Advisory, VDB Entry
- https://www.codeaurora.org/security-bulletin/2018/10/01/october-2018-code-aurora-security-bulletinPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.