CVE-2017-14888
Summary
| CVE | CVE-2017-14888 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-12-07 14:29:00 UTC |
| Updated | 2019-01-02 18:33:00 UTC |
| Description | In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Userspace can pass IEs to the host driver and if multiple append commands are received, then the integer variable that stores the length can overflow and the subsequent copy of the IE data may potentially lead to a heap buffer overflow. |
Risk And Classification
Problem Types: CWE-119
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| May 2018 Code Aurora Security Bulletin - Code Aurora | CONFIRM | www.codeaurora.org | Patch, Third Party Advisory |
| Pixel / Nexus Security Bulletin—November 2018 | CONFIRM | source.android.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 610347 Google Android May 2021 Security Patch Missing for Huawei EMUI