CVE-2017-14870
HIGHAndroid - Unauthorized Sensitive Information Exposure via eMMC Recovery Message Update
Title source: llmDescription
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while updating the recovery message for eMMC devices, 1088 bytes of stack memory can potentially be leaked.
References (1)
Core 1
Core References
Patch, Vendor Advisory x_refsource_confirm
https://source.android.com/security/bulletin/pixel/2018-01-01
Scores
CVSS v3
7.5
EPSS
0.0041
EPSS Percentile
33.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-200
Status
published
Products (1)
google/android
Published
Jan 10, 2018
Tracked Since
Feb 18, 2026