HIGH
In sample6 of SkSwizzler.cpp, there is a possible out of bounds write due to improper input validation
Published Feb 28, 2019
8.8
HIGHCVSS 3.0
EPSS 1.91%
Description
In sample6 of SkSwizzler.cpp, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution in system_server with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Android ID: A-118372692.
Affected products
-
- Version Android-8.0 Android-8.1 Android-9StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (3)
- http://www.securityfocus.com/bid/106842 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-10545 Advisory
- https://source.android.com/security/bulletin/2019-02-01 x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/106842 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-10545 | Advisory | |
| https://source.android.com/security/bulletin/2019-02-01 | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner google_android
Published Feb 28, 2019
Updated Sep 16, 2024
Reserved Dec 10, 2018
Link CVE-2019-1988
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2019-10545 Assigner google_android
Published Feb 28, 2019
Updated Sep 16, 2024
Exploited since n/a
Link EUVD-2019-10545