CVE-2019-2135
published 2019-08-20CVE-2019-2135: In Mfc_Transceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information…
PriorityP422medium5.5CVSS 3.0
AVLACLPRNUIRSUCHINAN
EPSS
0.50%
39.8th percentile
In Mfc_Transceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-125900276.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:C/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jvhr-f94x-68cm: In Mfc_Transceive of phNxpExtns_MifareStd
ghsa_unreviewed·2022-05-24
CVE-2019-2135 [HIGH] CWE-125 GHSA-jvhr-f94x-68cm: In Mfc_Transceive of phNxpExtns_MifareStd
In Mfc_Transceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-125900276.
Android
CVE-2019-2135: Android Security Bulletin 2019-08-01
CVE: CVE-2019-2135
Severity: HIGH
Type: ID
Affected AOSP versions: 7
vendor_android·2019-08-01·CVSS 5.5
CVE-2019-2135 [MEDIUM] CVE-2019-2135: Android Security Bulletin 2019-08-01
CVE: CVE-2019-2135
Severity: HIGH
Type: ID
Affected AOSP versions: 7
Android Security Bulletin 2019-08-01
CVE: CVE-2019-2135
Severity: HIGH
Type: ID
Affected AOSP versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1, 9
References: A-125900276
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-20079 vim: Use after free in window.c
bugzilla·2020-01-09·CVSS 7.8
CVE-2019-20079 [HIGH] CVE-2019-20079 vim: Use after free in window.c
CVE-2019-20079 vim: Use after free in window.c
The autocmd feature in window.c in Vim before 8.1.2136 accesses freed memory.
Upstream patch:
https://github.com/vim/vim/commit/ec66c41d84e574baf8009dbc0bd088d2bc5b2421
https://github.com/vim/vim/compare/v8.1.2135...v8.1.2136
Discussion:
Created vim tracking bugs for this issue:
Affects: fedora-all [bug 1789500]
---
Upstream issue:
https://github.com/vim/vim/issues/5041
---
The following commit introduces the vulnerability:
https://github.com/vim/vim/commit/a27e1dcddc9e3914ab34b164f71c51b72903b00b
This commit was first introduced in upstream version v8.1.2121.
---
Statement:
The versions of vim as shipped in Red Hat Enterprise Linux 5, 6, 7, and 8 are not affected by this flaw because the vulnerability was introduced in a newer
Bugzilla
CVE-2018-19869 qt5-qtsvg: Invalid parsing of malformed url reference resulting in a denial of service
bugzilla·2018-12-21·CVSS 6.5
CVE-2018-19869 [MEDIUM] CVE-2018-19869 qt5-qtsvg: Invalid parsing of malformed url reference resulting in a denial of service
CVE-2018-19869 qt5-qtsvg: Invalid parsing of malformed url reference resulting in a denial of service
It was found that qt-qtsvg incorrectly checks for the end of input while parsing url references. A malformed url reference could cause the application to crash.
References:
https://codereview.qt-project.org/#/c/234142/
Discussion:
Created mingw-qt5-qtsvg tracking bugs for this issue:
Affects: epel-7 [bug 1661464]
Affects: fedora-all [bug 1661461]
Created qt5-qtsvg tracking bugs for this issue:
Affects: epel-6 [bug 1661463]
Affects: fedora-all [bug 1661462]
---
Statement:
This issue affects the versions of qt5-qtsvg and qt as shipped with Red Hat Enterprise Linux 7.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2135 htt
Bugzilla
CVE-2018-19871 qt5-qtimageformats: QTgaFile CPU exhaustion
bugzilla·2018-12-21·CVSS 6.5
CVE-2018-19871 [MEDIUM] CVE-2018-19871 qt5-qtimageformats: QTgaFile CPU exhaustion
CVE-2018-19871 qt5-qtimageformats: QTgaFile CPU exhaustion
A TGA handler of QT imageformats incorrectly checks for large image sizes. A malformed image file could cause CPU exhaustion and denial of service.
References:
https://codereview.qt-project.org/#/c/237761/
Discussion:
Created mingw-qt5-qtimageformats tracking bugs for this issue:
Affects: epel-7 [bug 1661469]
Affects: fedora-all [bug 1661466]
Created qt5-qtimageformats tracking bugs for this issue:
Affects: epel-6 [bug 1661468]
Affects: fedora-all [bug 1661467]
---
Statement:
This issue affects the versions of qt5-qtimageformats and qt as shipped with Red Hat Enterprise Linux 7.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2135 https://access.redhat.com/errata
Bugzilla
CVE-2018-19870 qt5-qtbase: QImage allocation failure in qgifhandler
bugzilla·2018-12-13·CVSS 8.8
CVE-2018-19870 [HIGH] CVE-2018-19870 qt5-qtbase: QImage allocation failure in qgifhandler
CVE-2018-19870 qt5-qtbase: QImage allocation failure in qgifhandler
A possible QImage allocation failure was found in qgifhandler. A crafted file could cause the application to crash.
Upstream patch:
https://codereview.qt-project.org/#/c/235998/
Discussion:
Created mingw-qt5-qtbase tracking bugs for this issue:
Affects: epel-7 [bug 1659004]
Affects: fedora-all [bug 1659001]
Created qt5-qtbase tracking bugs for this issue:
Affects: epel-6 [bug 1659003]
Affects: fedora-all [bug 1659002]
---
Statement:
This issue affects the versions of qt5-base and qt as shipped with Red Hat Enterprise Linux 7.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2135 https://access.redhat.com/errata/RHSA-2019:2135
---
This bug is now closed.
Bugzilla
CVE-2018-19873 qt5-qtbase: QBmpHandler segmentation fault on malformed BMP file
bugzilla·2018-12-13·CVSS 9.8
CVE-2018-19873 [CRITICAL] CVE-2018-19873 qt5-qtbase: QBmpHandler segmentation fault on malformed BMP file
CVE-2018-19873 qt5-qtbase: QBmpHandler segmentation fault on malformed BMP file
A possible QBpmHandler segmentation fault on malformed BMP file. A crafted filed could cause the application to crash.
Upstream patch:
https://codereview.qt-project.org/#/c/238749/
Discussion:
Created mingw-qt5-qtbase tracking bugs for this issue:
Affects: epel-7 [bug 1659004]
Affects: fedora-all [bug 1659001]
Created qt5-qtbase tracking bugs for this issue:
Affects: epel-6 [bug 1659003]
Affects: fedora-all [bug 1659002]
---
Statement:
This issue affects the versions of qt5-base and qt as shipped with Red Hat Enterprise Linux 7.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2135 https://access.redhat.com/errata/RHSA-2019:2135
---
This bug
Bugzilla
CVE-2018-15518 qt5-qtbase: Double free in QXmlStreamReader
bugzilla·2018-12-13·CVSS 8.8
CVE-2018-15518 [HIGH] CVE-2018-15518 qt5-qtbase: Double free in QXmlStreamReader
CVE-2018-15518 qt5-qtbase: Double free in QXmlStreamReader
A possible double free and heap corruption was found in QXmlStream.
Upstream patch:
https://codereview.qt-project.org/#/c/236691/
Discussion:
Created mingw-qt5-qtbase tracking bugs for this issue:
Affects: epel-7 [bug 1659004]
Affects: fedora-all [bug 1659001]
Created qt5-qtbase tracking bugs for this issue:
Affects: epel-6 [bug 1659003]
Affects: fedora-all [bug 1659002]
---
Statement:
This issue affects the versions of qt5-base and qt as shipped with Red Hat Enterprise Linux 7.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2135 https://access.redhat.com/errata/RHSA-2019:2135
---
This bug is now closed. Further updates for individual products will be reflecte
2019-08-20
Published