Integer Overflow Vulnerability in ARM Trusted Firmware

Integer Overflow Vulnerability in ARM Trusted Firmware

CVE-2017-9607 · MEDIUM Severity

AV:N/AC:H/AU:N/C:P/I:P/A:P

The BL1 FWU SMC handling code in ARM Trusted Firmware before 1.4 might allow attackers to write arbitrary data to secure memory, bypass the bl1_plat_mem_check protection mechanism, cause a denial of service, or possibly have unspecified other impact via a crafted AArch32 image, which triggers an integer overflow.

Learn more about our Web Application Penetration Testing UK.