In libexif, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege in the media content provider with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112537774
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
History
21 Nov 2024, 04:51
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00000.html - Mailing List, Third Party Advisory | |
References | () http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00017.html - Mailing List, Third Party Advisory | |
References | () http://www.openwall.com/lists/oss-security/2019/10/25/17 - Mailing List | |
References | () http://www.openwall.com/lists/oss-security/2019/10/27/1 - Mailing List | |
References | () http://www.openwall.com/lists/oss-security/2019/11/07/1 - Mailing List | |
References | () https://github.com/libexif/libexif/commit/75aa73267fdb1e0ebfbc00369e7312bac43d0566 - Patch, Third Party Advisory | |
References | () https://github.com/libexif/libexif/issues/26 - Issue Tracking, Patch, Third Party Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2020/02/msg00007.html - Mailing List, Third Party Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MO2VTHD7OLPJDCJBHKUQTBAHZOBBCF6X/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VA5BPQLOFXIZOOJHBYDU635Z5KLUMTDD/ - | |
References | () https://seclists.org/bugtraq/2020/Feb/9 - Mailing List, Third Party Advisory | |
References | () https://security.gentoo.org/glsa/202007-05 - Third Party Advisory | |
References | () https://source.android.com/security/bulletin/android-10 - Vendor Advisory | |
References | () https://usn.ubuntu.com/4277-1/ - Third Party Advisory | |
References | () https://www.debian.org/security/2020/dsa-4618 - Third Party Advisory |
07 Nov 2023, 03:13
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2019-09-27 19:15
Updated : 2024-11-21 04:51
NVD link : CVE-2019-9278
Mitre link : CVE-2019-9278
CVE.ORG link : CVE-2019-9278
JSON object : View
Products Affected
opensuse
- leap
canonical
- ubuntu_linux
fedoraproject
- fedora
debian
- debian_linux
- android