CVE-2020-0018: Medium severity Google Android vulnerability
Published Feb 3, 2020
·Updated
In MotionEntry::appendDescription of InputDispatcher.cpp, there is a possible log information disclosure. This could lead to local disclosure of user input with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-139945049
Affected Software
5 affected components
Google Android=8.0
Google Android=8.1
Google Android=9.0
Google Android=10.0
Google Android
Remediation
Patch Available
Event History
Feb 3, 2020
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Feb 13, 2020
CVE Published
via MITRE·02:20 PM
Data Sourced
via MITRE·02:20 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-0018?
The severity of CVE-2020-0018 is medium with a CVSS score of 4.4.
2
What type of vulnerability is CVE-2020-0018?
CVE-2020-0018 is a possible log information disclosure vulnerability in the InputDispatcher component.
3
What systems are affected by CVE-2020-0018?
CVE-2020-0018 affects Android versions 8.0 and 8.1.
4
How do I fix CVE-2020-0018?
CVE-2020-0018 can be fixed by applying the available security patch.
5
Is user interaction required to exploit CVE-2020-0018?
No, user interaction is not needed to exploit CVE-2020-0018.