CVE-2018-5887 Information

Description

While processing the USB StrSerialDescriptor array an array index out of bounds can occur in Android releases from CAF using the linux kernel (Android for MSM Firefox OS for MSM QRD Android) before security patch level 2018-06-05.

CVSS Vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Reference

https://source.android.com/security/bulletin/pixel/2018-06-01qualcomm-components https://source.codeaurora.org/quic/la/abl/tianocore/edk2/commit/?id=c8415f6f2271008aef5056689950236df627d9b1

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

7.8

Share on: