9.8

CVE-2018-21054

An issue was discovered on Samsung mobile devices with M(6.0), N(7.x) and O(8.x) except exynos9610/9820 in all Platforms, M(6.0) except MSM8909 SC77xx/9830 exynos3470/5420, N(7.0) except MSM8939, N(7.1) except MSM8996 SDM6xx/M6737T software. There is an integer underflow with a resultant buffer overflow in eCryptFS. The Samsung ID is SVE-2017-11857 (September 2018).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Google ≫ Android Version 6.0
   Samsung ≫ Exynos 9610 Version -
   Samsung ≫ Exynos 9820 Version -
Google ≫ Android Version 7.0
   Samsung ≫ Exynos 9610 Version -
   Samsung ≫ Exynos 9820 Version -
Google ≫ Android Version 7.1.0
   Samsung ≫ Exynos 9610 Version -
   Samsung ≫ Exynos 9820 Version -
Google ≫ Android Version 7.1.1
   Samsung ≫ Exynos 9610 Version -
   Samsung ≫ Exynos 9820 Version -
Google ≫ Android Version 7.1.2
   Samsung ≫ Exynos 9610 Version -
   Samsung ≫ Exynos 9820 Version -
Google ≫ Android Version 8.0
   Samsung ≫ Exynos 9610 Version -
   Samsung ≫ Exynos 9820 Version -
Google ≫ Android Version 8.1
   Samsung ≫ Exynos 9610 Version -
   Samsung ≫ Exynos 9820 Version -
Google ≫ Android Version 6.0
   Qualcomm ≫ Msm8909 Version -
   Qualcomm ≫ Msm9830 Version -
   Samsung ≫ Exynos 3470 Version -
   Samsung ≫ Exynos 5420 Version -
   Unisoc ≫ Sc7715 Version -
   Unisoc ≫ Sc7730 Version -
   Unisoc ≫ Sc7731 Version -
Google ≫ Android Version 7.0
   Qualcomm ≫ Msm8939 Version -
Google ≫ Android Version 7.1
   Mediatek ≫ M6737t Version -
   Qualcomm ≫ Msm8996 Version -
   Qualcomm ≫ Sdm6xx Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.44% 0.35
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-190 Integer Overflow or Wraparound

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

https://security.samsungmobile.com/securityUpdate.smsb
Vendor Advisory