In extract3GPPGlobalDescriptions of TextDescriptions.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure from the media server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LAndroid ID: A-233735886
References
Link | Resource |
---|---|
https://source.android.com/security/bulletin/2022-09-01 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
08 Aug 2023, 14:21
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-191 |
Information
Published : 2022-09-13 20:15
Updated : 2024-02-28 19:29
NVD link : CVE-2022-20393
Mitre link : CVE-2022-20393
CVE.ORG link : CVE-2022-20393
JSON object : View
Products Affected
- android
CWE
CWE-191
Integer Underflow (Wrap or Wraparound)