CVE-2019-2033
published 2019-04-19CVE-2019-2033: In create_hdr of dnssd_clientstub.c, there is a possible use after free. This could lead to local escalation of privilege with no additional execution…
PriorityP339high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.17%
6.6th percentile
In create_hdr of dnssd_clientstub.c, there is a possible use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-121327565.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | android | — | — |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6ghp-6728-xfqc: In create_hdr of dnssd_clientstub
ghsa_unreviewed·2022-05-24
CVE-2019-2033 [HIGH] CWE-416 GHSA-6ghp-6728-xfqc: In create_hdr of dnssd_clientstub
In create_hdr of dnssd_clientstub.c, there is a possible use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-121327565.
Android
CVE-2019-2033: Android Security Bulletin 2019-04-01
CVE: CVE-2019-2033
Severity: HIGH
Type: EoP
Affected AOSP versions: 9
References: A-121327565
[2]
vendor_android·2019-04-01·CVSS 7.8
CVE-2019-2033 [HIGH] CVE-2019-2033: Android Security Bulletin 2019-04-01
CVE: CVE-2019-2033
Severity: HIGH
Type: EoP
Affected AOSP versions: 9
References: A-121327565
[2]
Android Security Bulletin 2019-04-01
CVE: CVE-2019-2033
Severity: HIGH
Type: EoP
Affected AOSP versions: 9
References: A-121327565
[2]
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-6952 patch: Double free of memory in pch.c:another_hunk() causes a crash
bugzilla·2018-02-14·CVSS 7.5
CVE-2018-6952 [HIGH] CVE-2018-6952 patch: Double free of memory in pch.c:another_hunk() causes a crash
CVE-2018-6952 patch: Double free of memory in pch.c:another_hunk() causes a crash
GNU patch through version 2.7.6 is vulnerable to a double freeing of memory when supplied a crafted patch file leading to a crash.
Upstream Issue:
https://savannah.gnu.org/bugs/index.php?53133
Discussion:
Created patch tracking bugs for this issue:
Affects: fedora-all [bug 1545054]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2033 https://access.redhat.com/errata/RHSA-2019:2033
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2018-6952
Bugzilla
CVE-2016-10713 patch: Out-of-bounds access in pch_write_line function in pch.c
bugzilla·2018-02-14·CVSS 5.5
CVE-2016-10713 [MEDIUM] CVE-2016-10713 patch: Out-of-bounds access in pch_write_line function in pch.c
CVE-2016-10713 patch: Out-of-bounds access in pch_write_line function in pch.c
A flaw was found in GNU patch before 2.7.6. An Out-of-bounds access within pch_write_line() function in pch.c file which can lead to a Denial of Service via a crafted input file.
External References:
https://savannah.gnu.org/bugs/index.php?45990
Upstream Patch:
https://git.savannah.gnu.org/cgit/patch.git/commit/src/pch.c?id=a0d7fe4589651c6
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2033 https://access.redhat.com/errata/RHSA-2019:2033
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2016-10713
2019-04-19
Published