CVE-2019-2105: High severity Google Android vulnerability
In FileInputStream::Read of fileinputstream.cc, there is a possible memory corruption due to uninitialized data. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-116114182.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-2105?
The severity of CVE-2019-2105 is considered to be high due to its potential for remote code execution.
How do I fix CVE-2019-2105?
To fix CVE-2019-2105, update your Android device to the latest version provided by your manufacturer.
What are the affected versions for CVE-2019-2105?
CVE-2019-2105 affects Android versions 7.0, 7.1.1, 7.1.2, 8.0, 8.1, and 9.0.
Is user interaction required for the exploitation of CVE-2019-2105?
Yes, user interaction is needed for the exploitation of CVE-2019-2105.
What kind of vulnerability is CVE-2019-2105 classified as?
CVE-2019-2105 is classified as a memory corruption vulnerability due to uninitialized data.