CVE-2019-2033: Use After Free
Published Apr 1, 2019
·Updated
In createhdr of dnssdclientstub.c, there is a possible use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-121327565.
Affected Software
2 affected components
Google Android=9.0
Google Android
Remediation
Patch Available
Event History
Apr 1, 2019
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Apr 19, 2019
CVE Published
via MITRE·07:36 PM
Data Sourced
via MITRE·07:36 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-2033?
CVE-2019-2033 has a high severity rating due to its potential for local escalation of privilege.
2
How do I fix CVE-2019-2033?
To fix CVE-2019-2033, you should update your Android device to a version beyond Android 9.0.
3
Who is affected by CVE-2019-2033?
CVE-2019-2033 affects users of Android 9.0.
4
Is user interaction required to exploit CVE-2019-2033?
No, user interaction is not needed for exploiting CVE-2019-2033.
5
What type of vulnerability is CVE-2019-2033?
CVE-2019-2033 is a use after free vulnerability in the dnssd_clientstub component.