CVE-2019-9232: High severity Google Android vulnerability
In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-122675483
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-9232?
CVE-2019-9232 is classified as a high severity vulnerability due to its potential for remote information disclosure.
How do I fix CVE-2019-9232?
To fix CVE-2019-9232, update libvpx to version 1.9.0-1+deb11u3 or later on Debian, or to the appropriate patched version on other affected systems.
Which software is affected by CVE-2019-9232?
CVE-2019-9232 affects libvpx across various distributions, including specific versions of Android, Ubuntu, openSUSE, and Fedora.
Can CVE-2019-9232 be exploited without user interaction?
Yes, CVE-2019-9232 can be exploited remotely and does not require user interaction for exploitation.
What type of vulnerability is CVE-2019-9232?
CVE-2019-9232 is an out of bounds read vulnerability due to a missing bounds check in libvpx.