CVE-2019-2116: High severity Google Android vulnerability
Published Jul 1, 2019
·Updated
In saveattrseq of sdpdiscovery.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-117105007.
Affected Software
7 affected components
Google Android=7.0
Google Android=7.1.1
Google Android=7.1.2
Google Android=8.0
Google Android=8.1
Google Android=9.0
Google Android
Event History
Jul 1, 2019
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Jul 8, 2019
CVE Published
via MITRE·05:39 PM
Data Sourced
via MITRE·05:39 PM
DescriptionWeakness
Frequently Asked Questions
1
Which Android releases are identified as affected?
The affected releases listed are Android 7.0, 7.1.1, 7.1.2, 8.0, 8.1, and 9.
2
What does an attacker need to exploit this issue?
The vulnerability is remotely exploitable with low attack complexity. It requires no privileges and no user interaction.
3
What is the security impact if exploitation succeeds?
Successful exploitation can disclose information remotely. The provided CVSS vector indicates high confidentiality impact, with no integrity or availability impact.