CVE-2019-2115
published 2019-09-05CVE-2019-2115: In GateKeeper::MintAuthToken of gatekeeper.cpp in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is possible memory corruption due to a double free. This could…
PriorityP338high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.27%
18.9th percentile
In GateKeeper::MintAuthToken of gatekeeper.cpp in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2019-2115: Android Security Bulletin 2019-09-01
CVE: CVE-2019-2115
Severity: HIGH
Type: EoP
Affected AOSP versions: 7
vendor_android·2019-09-01·CVSS 7.8
CVE-2019-2115 [HIGH] CVE-2019-2115: Android Security Bulletin 2019-09-01
CVE: CVE-2019-2115
Severity: HIGH
Type: EoP
Affected AOSP versions: 7
Android Security Bulletin 2019-09-01
CVE: CVE-2019-2115
Severity: HIGH
Type: EoP
Affected AOSP versions: 7.1.1, 7.1.2, 8.0, 8.1, 9
References: A-129768470
[2]
Red Hat
struts2: remote command execution due to flaw in the includeParams attribute of URL and Anchor tags
vendor_redhat·2013-05-22·CVSS 9.3
CVE-2013-2115 [CRITICAL] struts2: remote command execution due to flaw in the includeParams attribute of URL and Anchor tags
struts2: remote command execution due to flaw in the includeParams attribute of URL and Anchor tags
Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag. NOTE: this issue is due to an incomplete fix for CVE-2013-1966.
Statement: A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not included in any Red Hat products. This earlier statement was incorrect. While Struts 2 is not actively compiled, shipped, used, or enabled in any Red Hat provided final products, and does not cause any vulnerability in the product, struts2-core jars have been included in some products' source code packages.
GHSA
GHSA-78pf-52m8-mxjc: In GateKeeper::MintAuthToken of gatekeeper
ghsa_unreviewed·2022-05-24
CVE-2019-2115 [HIGH] CWE-415 GHSA-78pf-52m8-mxjc: In GateKeeper::MintAuthToken of gatekeeper
In GateKeeper::MintAuthToken of gatekeeper.cpp in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-09-05
Published