CVE-2017-17766
Last modified
CVE-2017-17766 is a vulnerability of currently unknown severity. In wma_peer_info_event_handler() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-03, the value of num_peers received from firmware is not properly validated so that an integer overflow vulnerability in the size of a buffer allocation may potentially lead to a buffer overflow.. EPSS estimates a 0.66% chance of exploitation in the next 30 days.
Description
In wma_peer_info_event_handler() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-03, the value of num_peers received from firmware is not properly validated so that an integer overflow vulnerability in the size of a buffer allocation may potentially lead to a buffer overflow.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-17766?
How severe is CVE-2017-17766?
How do I fix CVE-2017-17766?
Are you affected by CVE-2017-17766?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
