Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6cm8-m9g3-hrr7

Опубликовано: 16 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

In vorbis_book_decodev_set of codebook.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-199065614

In vorbis_book_decodev_set of codebook.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-199065614

EPSS

Процентиль: 65%
0.00502
Низкий

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 8.8
nvd
около 4 лет назад

In vorbis_book_decodev_set of codebook.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-199065614

CVSS3: 9.8
fstec
больше 4 лет назад

Уязвимость реализации функции vorbis_book_decodev_set() компонента Media Framework операционных систем Android, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации или выполнить произвольный код

EPSS

Процентиль: 65%
0.00502
Низкий

Дефекты

CWE-787