CVE-2019-2195: SQL Injection
Published Nov 4, 2019
·Updated
In tokenize of sqlite3android.cpp, there is a possible attacker controlled INSERT statement due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-139186193
Affected Software
5 affected components
Google Android=8.0
Google Android=8.1
Google Android=9.0
Google Android=10.0
Google Android
Event History
Nov 4, 2019
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Nov 13, 2019
CVE Published
via MITRE·05:32 PM
Data Sourced
via MITRE·05:32 PM
DescriptionWeakness
Frequently Asked Questions
1
Which Android versions are affected?
The affected versions listed are Android 8.0, 8.1, 9, and 10.
2
What level of access does an attacker need to exploit this issue?
Exploitation requires local access and low privileges. No user interaction or additional execution privileges are required.
3
What is the potential impact of successful exploitation?
A successful attack could allow local escalation of privilege and compromise confidentiality, integrity, and availability.