Out of Bounds Write Vulnerability in sdp_server.cc Could Lead to Remote Code Execution
CVE-2018-9479

9.8CRITICAL

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
20 November 2024

What is CVE-2018-9479?

The vulnerability exists in the SDP server of Android, specifically within the functions process_service_attr_req and process_service_search_attr_req in sdp_server.cc. An absence of bounds checking allows for an out of bounds write condition, which can be exploited to achieve remote code execution. This exploitation does not require any user interaction and can occur without additional execution privileges, potentially impacting device security significantly. Prompt application of security patches is recommended to mitigate this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Android 7

Android 8

Android 8.1

References

EPSS Score

5% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.