CVE-2020-0002: Use After Free
Published Jan 6, 2020
·Updated
In ih264dinitdecoder of ih264dapi.c, there is a possible out of bounds write due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation Product: Android Versions: Android-8.0, Android-8.1, Android-9, and Android-10 Android ID: A-142602711
Affected Software
5 affected components
Google Android=8.0
Google Android=8.1
Google Android=9.0
Google Android=10.0
Google Android
Remediation
Patch Available
Event History
Jan 6, 2020
CVE Published
via Android·12:00 AM
Jan 8, 2020
CVE Published
via MITRE·06:26 PM
Data Sourced
via MITRE·06:26 PM
DescriptionWeakness
Frequently Asked Questions
1
Which Android versions are affected?
The affected versions listed are Android 8.0, Android 8.1, Android 9, and Android 10.
2
What would an attacker need to exploit this issue?
The issue is remotely exploitable with low attack complexity and requires no privileges, but user interaction is required.
3
What is the potential impact of successful exploitation?
Successful exploitation could allow remote code execution. The CVSS vector indicates high impact to confidentiality, integrity, and availability.
4
Is a fix available?
Yes. A patch is available.