CVE-2024-40674

In validateSsid of WifiConfigurationUtil.java, there is a possible way to overflow a system configuration file due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Configurations

Configuration 1 (hide)

cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*

History

22 Apr 2025, 14:27

Type Values Removed Values Added
First Time Google
Google android
References () https://android.googlesource.com/platform/packages/modules/Wifi/+/debc548ac085ba1ab0582172b97d965e9a1ea43a - () https://android.googlesource.com/platform/packages/modules/Wifi/+/debc548ac085ba1ab0582172b97d965e9a1ea43a - Product
References () https://source.android.com/security/bulletin/2024-10-01 - () https://source.android.com/security/bulletin/2024-10-01 - Vendor Advisory
CPE cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*

03 Feb 2025, 16:15

Type Values Removed Values Added
Summary
  • (es) En validateSsid de WifiConfigurationUtil.java, existe una forma posible de desbordar el archivo de configuración sistema debido a un error lógico en el código. Esto podría provocar una denegación de servicio local sin necesidad de privilegios de ejecución adicionales. No se necesita la interacción del usuario para la explotación.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CWE CWE-120

28 Jan 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-28 20:15

Updated : 2025-04-22 14:27


NVD link : CVE-2024-40674

Mitre link : CVE-2024-40674

CVE.ORG link : CVE-2024-40674


JSON object : View

Products Affected

google

  • android
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')