In flattenString8 of Sensor.cpp, there is a possible information disclosure of heap memory due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0, Android-8.1, Android-9, and Android-10 Android ID: A-141890807
References
Link | Resource |
---|---|
https://source.android.com/security/bulletin/2020-01-01 | Vendor Advisory |
https://source.android.com/security/bulletin/2020-01-01 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2020-01-08 19:15
Updated : 2024-11-21 04:52
NVD link : CVE-2020-0007
Mitre link : CVE-2020-0007
CVE.ORG link : CVE-2020-0007
JSON object : View
Products Affected
- android
CWE
CWE-908
Use of Uninitialized Resource