| Vulnerability Name: | CVE-2017-18066 (CCN-140492) | ||||||||||||
| Assigned: | 2018-03-07 | ||||||||||||
| Published: | 2018-03-07 | ||||||||||||
| Updated: | 2018-04-04 | ||||||||||||
| Summary: | In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper controls in MSM CORE leads to use memory after it is freed in msm_core_ioctl(). | ||||||||||||
| CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||
| Vulnerability Type: | CWE-416 | ||||||||||||
| Vulnerability Consequences: | Gain Privileges | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2017-18066 Source: CCN Type: Google Web site Android Source: XF Type: UNKNOWN android-cve201718066-priv-esc(140492) Source: CCN Type: Android Open Source Project Pixel/Nexus Security BulletinMarch 2018 Source: CONFIRM Type: Vendor Advisory https://source.android.com/security/bulletin/pixel/2018-03-01 Source: MISC Type: Patch, Third Party Advisory https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=ff11f44c0c10c94170f03a8698f73f7e08b74625 | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||