cvelist/2019/9xxx/CVE-2019-9278.json

132 lines
5.2 KiB
JSON
Raw Normal View History

2019-02-28 13:04:56 -05:00
{
2019-09-27 19:01:17 +00:00
"data_type": "CVE",
"data_format": "MITRE",
"data_version": "4.0",
2019-03-18 07:16:51 +00:00
"CVE_data_meta": {
"ID": "CVE-2019-9278",
2019-09-27 19:01:17 +00:00
"ASSIGNER": "security@android.com",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "n/a",
"product": {
"product_data": [
{
"product_name": "Android",
"version": {
"version_data": [
{
"version_value": "Android-10"
}
]
}
}
]
}
}
]
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Remote code execution"
}
]
}
]
},
"references": {
"reference_data": [
{
"refsource": "MISC",
"name": "https://source.android.com/security/bulletin/android-10",
"url": "https://source.android.com/security/bulletin/android-10"
2019-10-26 00:01:08 +00:00
},
{
"refsource": "MLIST",
"name": "[oss-security] 20191025 Security fixes from Android 10 release which are relevant outside the Android ecosystem?",
"url": "http://www.openwall.com/lists/oss-security/2019/10/25/17"
2019-10-27 12:01:14 +00:00
},
{
"refsource": "MLIST",
"name": "[oss-security] 20191026 Re: Security fixes from Android 10 release which are relevant outside the Android ecosystem?",
"url": "http://www.openwall.com/lists/oss-security/2019/10/27/1"
2019-11-07 22:01:24 +00:00
},
{
"refsource": "MLIST",
"name": "[oss-security] 20191107 Re: Security fixes from Android 10 release which are relevant outside the Android ecosystem?",
"url": "http://www.openwall.com/lists/oss-security/2019/11/07/1"
2020-02-07 04:01:20 +00:00
},
{
"refsource": "DEBIAN",
"name": "DSA-4618",
"url": "https://www.debian.org/security/2020/dsa-4618"
2020-02-10 17:01:13 +00:00
},
{
"refsource": "MLIST",
"name": "[debian-lts-announce] 20200210 [SECURITY] [DLA 2100-1] libexif security update",
"url": "https://lists.debian.org/debian-lts-announce/2020/02/msg00007.html"
2020-02-10 19:01:08 +00:00
},
{
"refsource": "BUGTRAQ",
"name": "20200210 [SECURITY] [DSA 4618-1] libexif security update",
"url": "https://seclists.org/bugtraq/2020/Feb/9"
2020-02-11 17:01:09 +00:00
},
{
"refsource": "CONFIRM",
"name": "https://github.com/libexif/libexif/issues/26",
"url": "https://github.com/libexif/libexif/issues/26"
},
{
"refsource": "CONFIRM",
"name": "https://github.com/libexif/libexif/commit/75aa73267fdb1e0ebfbc00369e7312bac43d0566",
"url": "https://github.com/libexif/libexif/commit/75aa73267fdb1e0ebfbc00369e7312bac43d0566"
2020-02-19 00:01:05 +00:00
},
{
"refsource": "UBUNTU",
"name": "USN-4277-1",
"url": "https://usn.ubuntu.com/4277-1/"
2020-03-01 19:01:30 +00:00
},
{
"refsource": "SUSE",
"name": "openSUSE-SU-2020:0264",
"url": "http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00000.html"
2020-06-11 15:01:22 +00:00
},
{
"refsource": "SUSE",
"name": "openSUSE-SU-2020:0793",
"url": "http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00017.html"
2020-06-23 03:01:21 +00:00
},
{
"refsource": "FEDORA",
"name": "FEDORA-2020-b4db792558",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VA5BPQLOFXIZOOJHBYDU635Z5KLUMTDD/"
2020-06-25 03:01:16 +00:00
},
{
"refsource": "FEDORA",
"name": "FEDORA-2020-085150ac6e",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MO2VTHD7OLPJDCJBHKUQTBAHZOBBCF6X/"
2020-07-27 01:01:21 +00:00
},
{
"refsource": "GENTOO",
"name": "GLSA-202007-05",
"url": "https://security.gentoo.org/glsa/202007-05"
2019-09-27 19:01:17 +00:00
}
]
2019-03-18 07:16:51 +00:00
},
"description": {
"description_data": [
{
"lang": "eng",
2019-09-27 19:01:17 +00:00
"value": "In libexif, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege in the media content provider with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112537774"
2019-03-18 07:16:51 +00:00
}
]
}
}