CVE-2018-11280 Information
Feb 14, 2021
cve
Description
In all android releases (Android for MSM Firefox OS for MSM QRD Android) from CAF using the linux kernel while processing user-space there is no size validation of the NAT entry input. If the user input size of the NAT entry is greater than the max allowed size memory exhaustion will occur.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Reference
http://www.securityfocus.com/bid/106949 https://source.codeaurora.org/quic/la/kernel/msm-4.9/commit/?id=bd3627dae5f1a34e0284cfe167f61273ecc2f386 https://www.codeaurora.org/security-bulletin/2018/09/04/september-2018-code-aurora-security-bulletin
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
HIGH
Base Severity
5.5
Share on: