CVE-2019-2222: High severity Google Android vulnerability
n ihevcdparseslicedata of ihevcdparseslice.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-140322595
Affected Software
Event History
Frequently Asked Questions
Which Android releases are listed as affected?
Android 8.0, 8.1, 9, and 10 are listed as affected.
What level of access does an attacker need?
The CVSS vector indicates local attack access, no privileges, and required user interaction. Exploitation could result in remote code execution without additional execution privileges.
What is the potential impact if exploitation succeeds?
The out-of-bounds write can lead to remote code execution. The CVSS vector rates confidentiality, integrity, and availability impact as high.
What component is involved?
The issue is in ihevcd_parse_slice_data in ihevcd_parse_slice.c, within the Android libhevc component.