HIGH
In btif_dm_data_copy of btif_core.cc, there is a possible out of bounds write due to a buffer overflow
Published Feb 28, 2019
8.8
HIGHCVSS 3.0
EPSS 2.03%
Description
In btif_dm_data_copy of btif_core.cc, there is a possible out of bounds write due to a buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-110166268.
Affected products
-
- Version Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- http://www.securityfocus.com/bid/106946 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-10548 Advisory
- https://source.android.com/security/bulletin/2019-02-01 x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/106946 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-10548 | Advisory | |
| https://source.android.com/security/bulletin/2019-02-01 | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner google_android
Published Feb 28, 2019
Updated Sep 17, 2024
Reserved Dec 10, 2018
Link CVE-2019-1991
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2019-10548 Assigner google_android
Published Feb 28, 2019
Updated Sep 17, 2024
Exploited since n/a
Link EUVD-2019-10548