In flattenString8 of Sensor.cpp, there is a possible information disclosure of heap memory due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0, Android-8.1, Android-9, and Android-10 Android ID: A-141890807
References
Link | Resource |
---|---|
https://source.android.com/security/bulletin/2020-01-01 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-01-08 11:15
Updated : 2022-01-01 12:02
NVD link : CVE-2020-0007
Mitre link : CVE-2020-0007
JSON object : View
CWE
CWE-908
Use of Uninitialized Resource
Products Affected
- android