CVE-2019-20573
published 2020-03-24CVE-2019-20573: An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is local SQL injection in the RCS Content Provider. The…
PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.17%
6.4th percentile
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is local SQL injection in the RCS Content Provider. The Samsung IDs are SVE-2019-14059, SVE-2019-14685 (August 2019).
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-6285 yaml-cpp: DoS in SingleDocParser::HandleFlowSequence funtion
bugzilla·2019-01-21·CVSS 6.5
CVE-2019-6285 [MEDIUM] CVE-2019-6285 yaml-cpp: DoS in SingleDocParser::HandleFlowSequence funtion
CVE-2019-6285 yaml-cpp: DoS in SingleDocParser::HandleFlowSequence funtion
The SingleDocParser::HandleFlowSequence function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file.
References:
https://github.com/jbeder/yaml-cpp/issues/660
Discussion:
Created yaml-cpp tracking bugs for this issue:
Affects: epel-all [bug 1668107]
Affects: fedora-all [bug 1668106]
---
*** Bug 1686723 has been marked as a duplicate of this bug. ***
---
This is very likely a dupe of CVE-2018-20573.
---
Statement:
This issue affects the versions of rh-mongodb32-yaml-cpp, rh-mongodb34-yaml-cpp, and rh-mongodb36-yaml-cpp as shipped with Red Hat Software Collections. However, this is only used to parse co
Bugzilla
CVE-2019-6292 yaml-cpp: DoS in singledocparser.cpp
bugzilla·2019-01-21·CVSS 6.5
CVE-2019-6292 [MEDIUM] CVE-2019-6292 yaml-cpp: DoS in singledocparser.cpp
CVE-2019-6292 yaml-cpp: DoS in singledocparser.cpp
An issue was discovered in singledocparser.cpp in yaml-cpp (aka LibYaml-C++) 0.6.2. Stack Exhaustion occurs in YAML::SingleDocParser, and there is a stack consumption problem caused by recursive stack frames: HandleCompactMap, HandleMap, HandleFlowSequence, HandleSequence, HandleNode. Remote attackers could leverage this vulnerability to cause a denial-of-service via a cpp file.
References
https://github.com/jbeder/yaml-cpp/issues/657
Discussion:
This is very likely a dupe of CVE-2018-20573.
---
Created yaml-cpp tracking bugs for this issue:
Affects: epel-all [bug 1694684]
Affects: fedora-all [bug 1694683]
---
Statement:
This issue affects the versions of rh-mongodb32-yaml-cpp, rh-mongodb34-yaml-cpp, and rh-mongodb36-yaml-cpp as
2020-03-24
Published