ID

VAR-201903-1776


CVE

CVE-2018-14319


TITLE

(Pwn2Own) Samsung Galaxy S8 Shannon Stack-based Buffer Overflow Remote Code Execution Vulnerability

Trust: 0.7

sources: ZDI: ZDI-18-1450

DESCRIPTION

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S8. User interaction is required to exploit this vulnerability in that the target must answer a phone call.The specific flaw exists within the handling of Status Information Elements. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length, stack-based buffer. An attacker can leverage this vulnerability to execute code under the context of the baseband processor.

Trust: 0.7

sources: ZDI: ZDI-18-1450

AFFECTED PRODUCTS

vendor:samsungmodel:galaxy s8scope: - version: -

Trust: 0.7

sources: ZDI: ZDI-18-1450

CVSS

SEVERITY

CVSSV2

CVSSV3

ZDI: CVE-2018-14319
value: MEDIUM

Trust: 0.7

ZDI: CVE-2018-14319
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.7

sources: ZDI: ZDI-18-1450

PATCH

title: -> 2018 -> August -> SVE-2018-11828: Buffer Overflow in Exynos Chipset Devices with Security Patch Level (SPL) of August 1st, 2018 or later will include the patch for this issue.url:https://security.samsungmobile.com/securityupdate.smsb

Trust: 0.7

sources: ZDI: ZDI-18-1450

EXTERNAL IDS

db:NVDid:CVE-2018-14319

Trust: 0.7

db:ZDI_CANid:ZDI-CAN-5785

Trust: 0.7

db:ZDIid:ZDI-18-1450

Trust: 0.7

sources: ZDI: ZDI-18-1450

REFERENCES

url:https://security.samsungmobile.com/securityupdate.smsb

Trust: 0.7

sources: ZDI: ZDI-18-1450

CREDITS

acez

Trust: 0.7

sources: ZDI: ZDI-18-1450

SOURCES

db:ZDIid:ZDI-18-1450

LAST UPDATE DATE

2022-05-04T10:15:40.159000+00:00


SOURCES UPDATE DATE

db:ZDIid:ZDI-18-1450date:2019-03-05T00:00:00

SOURCES RELEASE DATE

db:ZDIid:ZDI-18-1450date:2019-03-04T00:00:00