Описание
A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml payload. This is due to an integer overflow in memory allocation for this string. The Samsung ID is SVE-2018-11463.
Ссылки
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- ExploitThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:o:samsung:samsung_mobile:6.0:*:*:*:*:*:*:*
cpe:2.3:o:samsung:samsung_mobile:7.0:*:*:*:*:*:*:*
cpe:2.3:o:samsung:samsung_mobile:7.1:*:*:*:*:*:*:*
cpe:2.3:o:samsung:samsung_mobile:7.1.1:*:*:*:*:*:*:*
cpe:2.3:o:samsung:samsung_mobile:7.1.2:*:*:*:*:*:*:*
EPSS
Процентиль: 94%
0.14356
Средний
5.3 Medium
CVSS3
5.4 Medium
CVSS2
Дефекты
CWE-190
Связанные уязвимости
CVSS3: 5.3
github
больше 3 лет назад
A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml payload. This is due to an integer overflow in memory allocation for this string. The Samsung ID is SVE-2018-11463.
EPSS
Процентиль: 94%
0.14356
Средний
5.3 Medium
CVSS3
5.4 Medium
CVSS2
Дефекты
CWE-190