First published: Mon Jul 01 2019(Updated: )
In FileInputStream::Read of file_input_stream.cc, there is a possible memory corruption due to uninitialized data. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-116114182.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =7.0 | |
Google Android | =7.1.1 | |
Google Android | =7.1.2 | |
Google Android | =8.0 | |
Google Android | =8.1 | |
Google Android | =9.0 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-2105 is considered to be high due to its potential for remote code execution.
To fix CVE-2019-2105, update your Android device to the latest version provided by your manufacturer.
CVE-2019-2105 affects Android versions 7.0, 7.1.1, 7.1.2, 8.0, 8.1, and 9.0.
Yes, user interaction is needed for the exploitation of CVE-2019-2105.
CVE-2019-2105 is classified as a memory corruption vulnerability due to uninitialized data.