CVE-2021-39689
published 2022-03-16CVE-2021-39689: In multiple functions of odsign_main.cpp, there is a possible way to persist system attack due to a logic error in the code. This could lead to local…
PriorityP428medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.10%
1.0th percentile
In multiple functions of odsign_main.cpp, there is a possible way to persist system attack due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-206090748
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | system_security | >= 12:0 < 12:2022-03-01 | 12:2022-03-01 |
| platform | system_security | >= 12L:0 < 12L:2022-03-01 | 12L:2022-03-01 |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cw6f-v7rm-qq56: In multiple functions of odsign_main
ghsa_unreviewed·2022-03-17
CVE-2021-39689 [HIGH] CWE-269 GHSA-cw6f-v7rm-qq56: In multiple functions of odsign_main
In multiple functions of odsign_main.cpp, there is a possible way to persist system attack due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-206090748
OSV
CVE-2021-39689: In multiple functions of odsign_main
osv·2022-03-01
CVE-2021-39689 CVE-2021-39689: In multiple functions of odsign_main
In multiple functions of odsign_main.cpp, there is a possible way to persist system attack due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Red Hat
python-certifi: Remove root certificates from `GLOBALTRUST` from the root store
vendor_redhat·2024-07-03·CVSS 7.5
CVE-2024-39689 [HIGH] CWE-345 python-certifi: Remove root certificates from `GLOBALTRUST` from the root store
python-certifi: Remove root certificates from `GLOBALTRUST` from the root store
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.5.30 and prior to 2024.7.4 recognized root certificates from `GLOBALTRUST`. Certifi 2024.7.04 removes root certificates from `GLOBALTRUST` from the root store. These are in the process of being removed from Mozilla's trust store. `GLOBALTRUST`'s root certificates are being removed pursuant to an investigation which identified "long-running and unresolved compliance issues."
A flaw was found in Certifi, a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hos
Android
CVE-2021-39689: Android Security Bulletin 2022-03-01
CVE: CVE-2021-39689
Severity: MEDIUM
Type: EoP
Affected AOSP versions: 12
References: A-206090748
vendor_android·2022-03-01·CVSS 6.7
CVE-2021-39689 [MEDIUM] CVE-2021-39689: Android Security Bulletin 2022-03-01
CVE: CVE-2021-39689
Severity: MEDIUM
Type: EoP
Affected AOSP versions: 12
References: A-206090748
Android Security Bulletin 2022-03-01
CVE: CVE-2021-39689
Severity: MEDIUM
Type: EoP
Affected AOSP versions: 12
References: A-206090748
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-03-16
Published