In FileInputStream::Read of file_input_stream.cc, there is a possible memory corruption due to uninitialized data. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-116114182.
References
Link | Resource |
---|---|
https://source.android.com/security/bulletin/2019-07-01 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2019-07-08 11:15
Updated : 2020-08-24 10:37
NVD link : CVE-2019-2105
Mitre link : CVE-2019-2105
JSON object : View
CWE
CWE-908
Use of Uninitialized Resource
Products Affected
- android