CVE-2019-9308
published 2019-09-27CVE-2019-9308: In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution…
PriorityP345high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.71%
49.6th percentile
In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112661742
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| libarchive | libarchive | >= 0 < 3.1.2-11ubuntu0.16.04.8 | 3.1.2-11ubuntu0.16.04.8 |
| libarchive | libarchive | >= 0 < 3.2.2-3.1ubuntu0.6 | 3.2.2-3.1ubuntu0.6 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xmrq-q3hv-6f55: In libAACdec, there is a possible out of bounds write due to an integer overflow
ghsa_unreviewed·2022-05-24
CVE-2019-9308 [MEDIUM] GHSA-xmrq-q3hv-6f55: In libAACdec, there is a possible out of bounds write due to an integer overflow
In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112661742
OSV
libarchive vulnerabilities
osv·2020-03-02·CVSS 5.5
CVE-2019-19221 libarchive vulnerabilities
libarchive vulnerabilities
It was discovered that libarchive incorrectly handled certain archive files.
An attacker could possibly use this issue to access sensitive information.
(CVE-2019-19221)
It was discovered that libarchive incorrectly handled certain archive files.
An attacker could possibly use this issue to cause a crash resulting in a denial
of service or possibly unspecified other impact. This issue only affected Ubuntu 19.10.
(CVE-2020-9308)
No detection rules found.
No writeups or analysis indexed.
2019-09-27
Published