CVE-2020-0383: Medium severity Google Android vulnerability
In Parseins of easmdls.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote information disclosure in the media extractor process with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android-8.0Android ID: A-150160279
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-0383?
CVE-2020-0383 has a medium severity rating due to potential remote information disclosure.
How do I fix CVE-2020-0383?
To mitigate CVE-2020-0383, upgrade to a patched version of Android that resolves the out of bounds write vulnerability.
What are the affected versions for CVE-2020-0383?
CVE-2020-0383 affects Android versions 8.0, 8.1, 9.0, 10.0, and 11.0.
What kind of user interaction is required for CVE-2020-0383 exploitation?
CVE-2020-0383 requires user interaction, such as opening a malicious media file, for exploitation to occur.
Can CVE-2020-0383 lead to system control?
No, CVE-2020-0383 does not lead to additional execution privileges or system control.