7.5
CVSSv2

CVE-2014-1909

Published: 14/05/2014 Updated: 30/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Integer signedness error in system/core/adb/adb_client.c in Android Debug Bridge (ADB) for Android 4.4 in the Android SDK Platform Tools 18.0.1 allows ADB servers to execute arbitrary code via a negative length value, which bypasses a signed comparison and triggers a stack-based buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse opensuse 12.3

opensuse opensuse 13.1

google android sdk platform tools 18.0.1

google android debug bridge -

Vendor Advisories

Debian Bug report logs - #770513 android-tools: CVE-2014-1909 Package: android-tools; Maintainer for android-tools is Android Tools Maintainers <android-tools-devel@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Fri, 21 Nov 2014 21:33:02 UTC Severity: grave Tags: security Fixed in v ...