CVE-2020-0240: Integer Overflow
Published Aug 3, 2020
·Updated
In NewFixedDoubleArray of factory.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-150706594
Affected Software
2 affected components
Google Android=10.0
Google Android
Event History
Aug 3, 2020
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Aug 11, 2020
CVE Published
via MITRE·07:27 PM
Data Sourced
via MITRE·07:27 PM
DescriptionWeakness
Frequently Asked Questions
1
Which Android releases are identified as affected?
The provided data identifies Android 10 as affected.
2
Does exploitation require an attacker to authenticate or obtain additional execution privileges first?
No. The CVSS vector indicates no privileges are required, and the description states that no additional execution privileges are needed.
3
Is user interaction required for exploitation?
Yes. The CVSS vector and description both indicate that exploitation requires user interaction.
4
What security impact could successful exploitation have?
Successful exploitation could lead to remote code execution. The CVSS metrics indicate high impact to confidentiality, integrity, and availability.