CVE-2024-0039: Buffer Overflow
Published Mar 4, 2024
·Updated
In attpbuildvaluecmd of attprotocol.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
5 affected components
Google Android=12.0
Google Android=12.1
Google Android=13.0
Google Android=14.0
Google Android
Remediation
Patch Available
Event History
Mar 4, 2024
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Mar 11, 2024
CVE Published
via MITRE·04:35 PM
Data Sourced
via MITRE·04:35 PM
DescriptionWeakness
Mar 13, 2024
News Published
via The Register·12:16 AM
News Published
via The Register·12:19 AM
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2024-0039?
CVE-2024-0039 is a high severity vulnerability that can lead to remote code execution.
2
How do I fix CVE-2024-0039?
To fix CVE-2024-0039, update your Android device to the latest security patch provided by Google.
3
Which versions of Android are affected by CVE-2024-0039?
CVE-2024-0039 affects Google Android versions 12.0, 12.1, 13.0, and 14.0.
4
Does CVE-2024-0039 require user interaction for exploitation?
No, CVE-2024-0039 does not require user interaction for exploitation.
5
What type of vulnerability is CVE-2024-0039?
CVE-2024-0039 is classified as an out of bounds write vulnerability.