Google Android Multiple Qualcomm Components Multiple Security Vulnerabilities
BID:102073
CVE-2017-9716 |Info
Google Android Multiple Qualcomm Components Multiple Security Vulnerabilities
| Bugtraq ID: | 102073 |
| Class: | Unknown |
| CVE: |
CVE-2017-11043 CVE-2017-11007 CVE-2017-14904 CVE-2017-9716 CVE-2017-14897 CVE-2017-14902 CVE-2017-14895 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 04 2017 12:00AM |
| Updated: | May 15 2019 04:00PM |
| Credit: | The vendor reported these issues. |
| Vulnerable: |
Google Android 0 |
| Not Vulnerable: | |
Discussion
Google Android Multiple Qualcomm Components Multiple Security Vulnerabilities
Google Android is prone to the following security vulnerabilities:
1. Multiple remote-code execution vulnerabilities
2. Multiple privilege-escalation vulnerabilities
An attacker can exploit these issues to gain elevated privileges or execute arbitrary code. Failed exploits may result in a denial-of-service condition.
Google Android is prone to the following security vulnerabilities:
1. Multiple remote-code execution vulnerabilities
2. Multiple privilege-escalation vulnerabilities
An attacker can exploit these issues to gain elevated privileges or execute arbitrary code. Failed exploits may result in a denial-of-service condition.
Exploit / POC
Google Android Multiple Qualcomm Components Multiple Security Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Google Android Multiple Qualcomm Components Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Google Android Multiple Qualcomm Components Multiple Security Vulnerabilities
References:
References:
- Android Homepage (Google)
- Android Security Bulletin�??December 2017 (Android)
- CVE-2016-3706: getaddrinfo: stack overflow in hostent conversion [BZ #20010] (CodeAurora)
- qbt1000: Validate FP app name before qseecom_start_app (CodeAurora)
- qcacld-2.0: Add bound check for numap to avoid integer overflow (CodeAurora)
- qcacld-3.0: update hw/sw info afer modules get closed (CodeAurora)
- QcomModulePkg: Add check on max partition name length (CodeAurora)
- qseecom: Fix accessing userspace memory in kernel space (CodeAurora)
- soc: qcom: glink: Remove magic number logic (CodeAurora)