CVE-2019-2051: Input Validation
In heap of spaces.h, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure when processing a proxy auto config file with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9 Android ID: A-117555811
Affected Software
Event History
Frequently Asked Questions
Which Android releases are identified as affected?
The affected releases listed are Android 7.0, 7.1.1, 7.1.2, 8.0, 8.1, and 9.
What must an attacker do to exploit this issue?
An attacker needs to cause the device to process a proxy auto-configuration (PAC) file containing invalid input. The issue is remotely exploitable, requires no privileges, and does not require user interaction.
What is the expected impact of successful exploitation?
Successful exploitation can disclose information remotely through an out-of-bounds read in spaces.h. The provided CVSS vector indicates high confidentiality impact, with no integrity or availability impact.