CVE-2019-1991: Buffer Overflow
In btifdmdatacopy of btifcore.cc, there is a possible out of bounds write due to a buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-110166268.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1991?
CVE-2019-1991 is rated as a critical vulnerability due to its potential to allow remote code execution.
Which Android versions are affected by CVE-2019-1991?
CVE-2019-1991 affects Android versions 7.0, 7.1.1, 7.1.2, 8.0, 8.1, and 9.0.
How do I fix CVE-2019-1991?
To fix CVE-2019-1991, update your device to the latest Android security patch provided by Google.
What kind of attack vector is used to exploit CVE-2019-1991?
CVE-2019-1991 can be exploited through user interaction, making it necessary for users to open a malicious file or application.
What are the consequences of exploiting CVE-2019-1991?
Exploiting CVE-2019-1991 could result in an out of bounds write leading to remote code execution without requiring additional privileges.