CVE-2018-11295
CVE-2018-11295
Vexday Risk Score
3Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS —EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
18 set 2018Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, WMA handler carries a fixed event data from the firmware to the host . If the length and anqp length from this event data exceeds the max length, an OOB write would happen.
Produtos afetados
Qualcomm, Inc. · Android for MSM, Firefox OS for MSM, QRD AndroidReferências
https://source.android.com/security/bulletin/pixel/2018-09-01#qualcomm-componentshttps://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-3.0/commit/?id=e262728243f98d8a3578eb157cbc39580004de4fhttps://www.codeaurora.org/security-bulletin/2018/09/04/september-2018-code-aurora-security-bulletin