CVE-2017-13259
Description
In functionality implemented in sdp_discovery.cc, there are possible out of bounds reads due to missing bounds checks. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68161546.
CWE
- (none)
Affected
- Google Inc. / Android — v=5.1.1 [affected]; v=6.0 [affected]; v=6.0.1 [affected]; v=7.0 [affected]; v=7.1.1 [affected]; v=7.1.2 [affected]; v=8.0 [affected]; v=8.1 [affected]
CVSS
- (none)
References
- https://source.android.com/security/bulletin/2018-03-01 x_refsource_CONFIRM
- http://www.securityfocus.com/bid/103253 vdb-entry, x_refsource_BID
Source
cvelistV5-main/cves/2017/13xxx/CVE-2017-13259.json