Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-11828

Опубликовано: 21 апр. 2020
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

In ColorOS (oppo mobile phone operating system, based on AOSP frameworks/native code position/services/surfaceflinger surfaceflinger.CPP), RGB is defined on the stack but uninitialized, so when the screenShot function to RGB value assignment, will not initialize the value is returned to the attackers, leading to values on the stack information leakage, the vulnerability can be used to bypass attackers ALSR.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:oppo:coloros:-:*:*:*:*:*:*:*

EPSS

Процентиль: 54%
0.00316
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-908

Связанные уязвимости

github
больше 3 лет назад

In ColorOS (oppo mobile phone operating system, based on AOSP frameworks/native code position/services/surfaceflinger surfaceflinger.CPP), RGB is defined on the stack but uninitialized, so when the screenShot function to RGB value assignment, will not initialize the value is returned to the attackers, leading to values on the stack information leakage, the vulnerability can be used to bypass attackers ALSR.

EPSS

Процентиль: 54%
0.00316
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-908