CVE-2020-0017: Medium severity Google Android vulnerability
Published Feb 3, 2020
·Updated
In multiple places, it was possible for the primary user’s dictionary to be visible to and modifiable by secondary users. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-123232892
Affected Software
5 affected components
Google Android=8.0
Google Android=8.1
Google Android=9.0
Google Android=10.0
Google Android
Remediation
Patch Available
Event History
Feb 3, 2020
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Feb 13, 2020
CVE Published
via MITRE·02:20 PM
Data Sourced
via MITRE·02:20 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-0017?
The severity of CVE-2020-0017 is rated as medium with a CVSS score of 4.4.
2
How do I fix CVE-2020-0017?
You can fix CVE-2020-0017 by applying the available patch provided by Google.
3
What kind of information can be disclosed due to CVE-2020-0017?
CVE-2020-0017 can lead to local information disclosure of the primary user’s dictionary by secondary users.
4
What user action is required to exploit CVE-2020-0017?
User interaction is necessary for the exploitation of CVE-2020-0017.
5
In which versions of Android does CVE-2020-0017 exist?
CVE-2020-0017 exists in Android 8.0 and potentially other versions.