CVE-2020-0409: Integer Overflow
Published Nov 2, 2020
·Updated
In create of FileMap.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-8.0 Android-8.1 Android-9Android ID: A-156997193
Affected Software
5 affected components
Google Android=8.0
Google Android=8.1
Google Android=9.0
Google Android=10.0
Google Android
Remediation
Patch Available
Event History
Nov 2, 2020
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Nov 10, 2020
CVE Published
via MITRE·12:48 PM
Data Sourced
via MITRE·12:48 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-0409.
2
What is the severity of CVE-2020-0409?
CVE-2020-0409 has a severity rating of 7.8 (high).
3
How does CVE-2020-0409 impact Android?
CVE-2020-0409 could lead to local escalation of privilege on Android devices.
4
Is user interaction required for exploitation of CVE-2020-0409?
No, user interaction is not needed for exploitation of CVE-2020-0409.
5
How can I fix the vulnerability CVE-2020-0409?
To fix the vulnerability CVE-2020-0409, it is recommended to apply the necessary patches and updates provided by Google for the affected Android versions.