cvelist/2019/2xxx/CVE-2019-2007.json

62 lines
2.0 KiB
JSON
Raw Normal View History

2018-12-10 10:08:48 -05:00
{
2019-06-19 20:00:46 +00:00
"data_type": "CVE",
"data_format": "MITRE",
"data_version": "4.0",
2019-03-18 05:40:22 +00:00
"CVE_data_meta": {
"ID": "CVE-2019-2007",
2019-06-19 20:00:46 +00:00
"ASSIGNER": "security@android.com",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "n/a",
"product": {
"product_data": [
{
"product_name": "Android",
"version": {
"version_data": [
{
"version_value": "Android-8.1 Android-9"
}
]
}
}
]
}
}
]
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Elevation of privilege"
}
]
}
]
},
"references": {
"reference_data": [
{
"refsource": "MISC",
"name": "https://source.android.com/security/bulletin/2019-03-01",
"url": "https://source.android.com/security/bulletin/2019-03-01"
}
]
2019-03-18 05:40:22 +00:00
},
"description": {
"description_data": [
{
"lang": "eng",
2019-06-19 20:00:46 +00:00
"value": "In getReadIndex and getWriteIndex of FifoControllerBase.cpp, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege in the audio server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9Android ID: A-120789744"
2019-03-18 05:40:22 +00:00
}
]
}
}