Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6jfc-jv5m-vxv3

Опубликовано: 15 янв. 2022
Источник: github
Github: Не прошло ревью

Описание

In sec_SHA256_Transform of sha256_core.c, there is a possible way to read heap data due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-197965864References: N/A

In sec_SHA256_Transform of sha256_core.c, there is a possible way to read heap data due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-197965864References: N/A

EPSS

Процентиль: 3%
0.00016
Низкий

Дефекты

CWE-908

Связанные уязвимости

CVSS3: 4.4
nvd
около 4 лет назад

In sec_SHA256_Transform of sha256_core.c, there is a possible way to read heap data due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-197965864References: N/A

EPSS

Процентиль: 3%
0.00016
Низкий

Дефекты

CWE-908