Possible Resource Exhaustion in ID3.cpp May Lead to Denial of Service
CVE-2018-9412

5.5MEDIUM

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
19 November 2024

What is CVE-2018-9412?

A resource exhaustion vulnerability has been identified in the ID3 audio metadata processing within the Android platform. This flaw arises from improper input validation in the removeUnsynchronization function located in ID3.cpp. By providing specially crafted input, an attacker can exploit this vulnerability to trigger excessive resource usage, potentially leading to a denial of service. While user interaction is required for exploitation, the lack of additional execution privileges makes this vulnerability significant in the context of application security and system reliability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Android 6

Android 6.0.1

Android 7

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.