On Audi A7 MMI 2014 vehicles, the Bluetooth stack in Audi A7 MMI Multiplayer with version (N+R_CN_AU_P0395) mishandles %x and %s format string specifiers in a device name. This may lead to memory content leaks and potentially crash the services.
References
Link | Resource |
---|---|
https://tiger-team-1337.blogspot.com/2020/10/audi-a7-2014-mmi-mishandles-format.html | Exploit Third Party Advisory |
https://twitter.com/Kevin2600/status/1316380576593571840 | Third Party Advisory |
https://www.youtube.com/watch?v=BQUVgAdhwQs | Exploit Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2020-11-11T14:20:56
Updated: 2020-11-11T14:20:55
Reserved: 2020-10-21T00:00:00
Link: CVE-2020-27524
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-11-11T15:15:11.357
Modified: 2020-12-30T15:12:57.913
Link: CVE-2020-27524
JSON object: View
Redhat Information
No data.
CWE