Required CVE Record Information
Description
In Bitmap.ccp if Bitmap.nativeCreate fails an out of memory exception is not thrown leading to a java.io.IOException later on. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-33846679.
References 3 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 3 Total
- https://source.android.com/security/bulletin/2018-01-01 x_transferred
- securitytracker.com: 1040106 vdb-entryx_transferred
- securityfocus.com: 102414 vdb-entryx_transferred