CVE-2018-9504

In sdp_copy_raw_data of sdp_discovery.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution over bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-110216176
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:google:android:7.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:7.1.1:*:*:*:*:*:*:*
cpe:2.3:o:google:android:7.1.2:*:*:*:*:*:*:*
cpe:2.3:o:google:android:8.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:8.1:*:*:*:*:*:*:*
cpe:2.3:o:google:android:9.0:*:*:*:*:*:*:*

History

21 Nov 2024, 04:15

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/105482 - VDB Entry, Third Party Advisory () http://www.securityfocus.com/bid/105482 - Third Party Advisory, VDB Entry
References () https://android.googlesource.com/platform/system/bt/+/11fb7aa03437eccac98d90ca2de1730a02a515e2 - Patch, Vendor Advisory () https://android.googlesource.com/platform/system/bt/+/11fb7aa03437eccac98d90ca2de1730a02a515e2 - Patch, Vendor Advisory
References () https://source.android.com/security/bulletin/2018-10-01%2C - () https://source.android.com/security/bulletin/2018-10-01%2C -

07 Nov 2023, 03:01

Type Values Removed Values Added
References
  • {'url': 'https://source.android.com/security/bulletin/2018-10-01,', 'name': 'https://source.android.com/security/bulletin/2018-10-01,', 'tags': ['Broken Link'], 'refsource': 'CONFIRM'}
  • () https://source.android.com/security/bulletin/2018-10-01%2C -

Information

Published : 2018-10-02 19:29

Updated : 2024-11-21 04:15


NVD link : CVE-2018-9504

Mitre link : CVE-2018-9504

CVE.ORG link : CVE-2018-9504


JSON object : View

Products Affected

google

  • android
CWE
CWE-787

Out-of-bounds Write