In ffu_flash_pack of ffu.c, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
Metrics
Affected Vendors & Products
References
History
Mon, 28 Oct 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-190 | |
CPEs | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
Fri, 25 Oct 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Google
Google android Google pixel |
|
Weaknesses | CWE-125 | |
CPEs | cpe:2.3:h:google:pixel:*:*:*:*:*:*:*:* cpe:2.3:o:google:android:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Google
Google android Google pixel |
|
Metrics |
cvssV3_1
|
Fri, 25 Oct 2024 10:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In ffu_flash_pack of ffu.c, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: Google_Devices
Published: 2024-10-25T10:34:06.682Z
Updated: 2024-10-25T16:12:38.787Z
Reserved: 2024-09-16T19:14:14.860Z
Link: CVE-2024-47028
Vulnrichment
Updated: 2024-10-25T15:58:36.602Z
NVD
Status : Analyzed
Published: 2024-10-25T11:15:17.280
Modified: 2024-10-28T17:58:00.427
Link: CVE-2024-47028
Redhat
No data.