Exploit/Advisories Cybersecurity study of the dark web exposes vulnerability to machine identities -- ScienceDaily

Published on July 9th, 2019 📆 | 8412 Views ⚑

0

Google Android up to 9.0 ihevcd_sao.c ihevcd_sao_shift_ctb memory corruption


TTS

CVSS Meta Temp Score Current Exploit Price (β‰ˆ)
6.0 $5k-$25k

A vulnerability, which was classified as critical, has been found in Google Android up to 9.0 (Smartphone Operating System). Affected by this issue is the function ihevcd_sao_shift_ctb of the file ihevcd_sao.c. The manipulation with an unknown input leads to a memory corruption vulnerability (Out-of-Bounds). Using CWE to declare the problem leads to CWE-119. Impacted is confidentiality, integrity, and availability.

The weakness was released 07/08/2019. The advisory is available at source.android.com. This vulnerability is handled as CVE-2019-2106 since 12/10/2018. The attack may be launched remotely. No form of authentication is required for exploitation. Technical details are known, but there is no available exploit. The structure of the vulnerability defines a possible price range of USD $5k-$25k at the moment (estimation calculated on 07/09/2019). It is expected to see the exploit prices for this product increasing in the near future.

Applying a patch is able to eliminate this problem.

Entries connected to this vulnerability are available at 137484, 137485, 137487 and 137488.

Type

Vendor

Name

VulDB Meta Base Score: 6.3
VulDB Meta Temp Score: 6.0

VulDB Base Score: 6.3
VulDB Temp Score: 6.0
VulDB Vector: πŸ”’
VulDB Reliability: πŸ”

AV AC Au C I A
πŸ” πŸ” πŸ” πŸ” πŸ” πŸ”
πŸ” πŸ” πŸ” πŸ” πŸ” πŸ”
πŸ” πŸ” πŸ” πŸ” πŸ” πŸ”
Vector Complexity Authentication Confidentiality Integrity Availability
unlock unlock unlock unlock unlock unlock
unlock unlock unlock unlock unlock unlock
unlock unlock unlock unlock unlock unlock


VulDB Base Score: πŸ”’
VulDB Temp Score: πŸ”’
VulDB Reliability: πŸ”
Class: Memory corruption / Out-of-Bounds (CWE-119)
Local: No
Remote: Yes

Availability: πŸ”’
Status: Not defined





Price Prediction: πŸ”
Current Price Estimation: πŸ”’


0-Day unlock unlock unlock unlock
Today unlock unlock unlock unlock

Threat Intelligenceinfoedit

Threat: πŸ”
Adversaries: πŸ”
Geopolitics: πŸ”
Economy: πŸ”
Predictions: πŸ”
Remediation: πŸ”Recommended: Patch
Status: πŸ”

0-Day Time: πŸ”’

12/10/2018 CVE assigned
07/08/2019 +210 days Advisory disclosed
07/09/2019 +1 days VulDB entry created
07/09/2019 +0 days VulDB last updateVendor: google.com

Advisory: source.android.com

CVE: CVE-2019-2106 (πŸ”’)
scip Labs: https://www.scip.ch/en/?labs.20150917
See also: πŸ”’

Created: 07/09/2019 08:16 AM
Complete: πŸ”

Comments

No comments yet. Please log in to comment.

Use the official API to access entries easily!

https://vuldb.com/?id.137486

Tagged with: β€’ β€’ β€’ β€’ β€’



Comments are closed.