CVE-2018-9565
Description
In readBytes of xltdecwbxml.c, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-16680558.
CWE
- (none)
Affected
- Google Inc. / Android — v=Android-16680558 [affected]
CVSS
- (none)
References
- http://www.securityfocus.com/bid/106065 vdb-entry, x_refsource_BID
- https://source.android.com/security/bulletin/2018-12-01 x_refsource_CONFIRM
Source
cvelistV5-main/cves/2018/9xxx/CVE-2018-9565.json