← Back

CVE-2018-9475

nvd nist
Published: Nov 20, 2024Modified: Dec 18, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

In HeadsetInterface::ClccResponse of btif_hf.cc, there is a possible out of bounds stack write due to a missing bounds check. This could lead to remote escalation of privilege via Bluetooth, if the recipient has enabled SIP calls with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected (6)

Products: Google: Android
1 product
Android
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Google
Version 7.0
Version 7.1.1
Version 7.1.2
Version 8.0
Version 8.1
Version 9.0

References (1)

Source: security@android.com
PatchVendor Advisory

Timeline

No history available yet.