Android KeyStore Buffer Overflow (CVE-2014-3100)
We have discovered a stack-based buffer overflow in the Android KeyStore service which affects Android 4.3.
The issue was patched in Android 4.4.
As an anecdote, the vulnerable source code contains the following comment:
Though things are simple, buffers are not always larger than the maximum space they needed. The vulnerability is identified as CVE-2014-3100.
More details are available at:
1. Blog post: http://ibm.co/1pbk4yH
2. Advisory: http://slidesha.re/1nxBnmY
The issue was patched in Android 4.4.
As an anecdote, the vulnerable source code contains the following comment:
Though things are simple, buffers are not always larger than the maximum space they needed. The vulnerability is identified as CVE-2014-3100.
More details are available at:
1. Blog post: http://ibm.co/1pbk4yH
2. Advisory: http://slidesha.re/1nxBnmY