CVE-2021-0966
published 2021-12-15CVE-2021-0966: In code generated by BuildParcelFields of generate_cpp.cpp, there is a possible way for a crafted parcelable to reveal uninitialized memory of a target process…
PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.11%
1.5th percentile
In code generated by BuildParcelFields of generate_cpp.cpp, there is a possible way for a crafted parcelable to reveal uninitialized memory of a target process due to uninitialized data. This could lead to local information disclosure across Binder transactions with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-198346478
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | system_tools_aidl | >= 11:0 < 11:2021-12-01 | 11:2021-12-01 |
| platform | system_tools_aidl | >= 12:0 < 12:2021-12-01 | 12:2021-12-01 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f73v-rm28-j7c4: In code generated by BuildParcelFields of generate_cpp
ghsa_unreviewed·2021-12-16
CVE-2021-0966 [MEDIUM] CWE-668 GHSA-f73v-rm28-j7c4: In code generated by BuildParcelFields of generate_cpp
In code generated by BuildParcelFields of generate_cpp.cpp, there is a possible way for a crafted parcelable to reveal uninitialized memory of a target process due to uninitialized data. This could lead to local information disclosure across Binder transactions with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-198346478
OSV
CVE-2021-0966: In code generated by BuildParcelFields of generate_cpp
osv·2021-12-01
CVE-2021-0966 CVE-2021-0966: In code generated by BuildParcelFields of generate_cpp
In code generated by BuildParcelFields of generate_cpp.cpp, there is a possible way for a crafted parcelable to reveal uninitialized memory of a target process due to uninitialized data. This could lead to local information disclosure across Binder transactions with no additional execution privileges needed. User interaction is not needed for exploitation.
Android
CVE-2021-0966: Android Security Bulletin 2021-12-01
CVE: CVE-2021-0966
Severity: HIGH
Type: ID
Affected AOSP versions: 11, 12
References: A-198346478
vendor_android·2021-12-01·CVSS 5.5
CVE-2021-0966 [MEDIUM] CVE-2021-0966: Android Security Bulletin 2021-12-01
CVE: CVE-2021-0966
Severity: HIGH
Type: ID
Affected AOSP versions: 11, 12
References: A-198346478
Android Security Bulletin 2021-12-01
CVE: CVE-2021-0966
Severity: HIGH
Type: ID
Affected AOSP versions: 11, 12
References: A-198346478
Red Hat
pki-core: Unprivileged users can renew any certificate
vendor_redhat·2021-03-12·CVSS 8.1
CVE-2021-20179 [HIGH] CWE-863 pki-core: Unprivileged users can renew any certificate
pki-core: Unprivileged users can renew any certificate
A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and integrity.
A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and integrity.
Statement: - Red Hat Certificate System 10.1 has been fixed via the Red Hat Enterprise Linux 8 errata RHSA-2021:0966
- Red Hat Certificate System 10.2 and newer are not
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-12-15
Published