In bta_hd_set_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation.
References
Link | Resource |
---|---|
https://source.android.com/security/bulletin/2018-09-01 |
Configurations
No configuration.
History
20 Nov 2024, 19:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-125 CWE-190 |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.2 |
20 Nov 2024, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-11-20 18:15
Updated : 2024-11-20 19:35
NVD link : CVE-2018-9481
Mitre link : CVE-2018-9481
CVE.ORG link : CVE-2018-9481
JSON object : View
Products Affected
No product.