CVE-2019-2201Out-of-bounds Write in Google Android

Severity
7.8HIGHNVD
OSV6.5
EPSS
1.1%
top 22.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 13
Latest updateMay 24

Description

In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-120551338

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages6 packages

CVEListV5google/androidAndroid-8.0 Android-8.1 Android-9 Android-10
NVDgoogle/android4 versions+3
debiandebian/libjpeg-turbo< libjpeg-turbo 1:2.0.5-1 (bookworm)
Debianlibjpeg-turbo/libjpeg-turbo< 1:2.0.5-1+3

Also affects: Ubuntu Linux 16.04, 18.04, 19.04

🔴Vulnerability Details

3
GHSA
GHSA-x9wg-q72x-x5w7: In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon2022-05-24
OSV
CVE-2019-2201: In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon2019-11-13
OSV
libjpeg-turbo vulnerabilities2019-11-13

📋Vendor Advisories

4
Ubuntu
libjpeg-turbo vulnerabilities2019-11-13
Android
CVE-2019-2201: Android Security Bulletin 2019-11-01 CVE: CVE-2019-2201 Severity: HIGH Type: RCE Affected AOSP versions: 82019-11-01
Red Hat
libjpeg-turbo: several integer overflows and subsequent segfaults when attempting to compress/decompress gigapixel images2019-07-05
Debian
CVE-2019-2201: libjpeg-turbo - In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possibl...2019

💬Community

9
Bugzilla
libjpeg-turbo: out-of-bounds write in tjDecompressToYUV2() and tjDecompressToYUVPlanes()2020-06-24
Bugzilla
libjpeg-turbo: decompression of images greater than 715827882 pixels causing integer overflow2020-06-24
Bugzilla
CVE-2019-2201 mingw-libjpeg-turbo: libjpeg-turbo: several integer overflows and subsequent segfaults when attempting to compress/decompress gigapixel images [fedora-all]2019-11-11
Bugzilla
CVE-2019-2201 libjpeg-turbo: several integer overflows and subsequent segfaults when attempting to compress/decompress gigapixel images2019-11-11
Bugzilla
CVE-2019-2201 mingw-libjpeg-turbo: libjpeg-turbo: several integer overflows and subsequent segfaults when attempting to compress/decompress gigapixel images [epel-7]2019-11-11