← Back

CVE-2017-13290

nvd nist
Published: Apr 4, 2018Modified: Nov 21, 2024

JSON object

Loading...
6.2
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.5 / Impact: 3.6
Source: NVD

Description

In sdp_server_handle_client_req of sdp_server.cc, there is an out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-69384124.

Affected (7)

Products: Google: Android
1 product
Android
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Google
Version 6.0.1
Version 6.0
Version 7.0
Version 7.1.1
Version 7.1.2
Version 8.0
Version 8.1

References (2)

Source: security@android.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.