CVE-2022-20202
published 2022-06-15CVE-2022-20202: In ih264_resi_trans_quant_4x4_sse42 of ih264_resi_trans_quant_sse42.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to…
PriorityP432medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.65%
46.7th percentile
In ih264_resi_trans_quant_4x4_sse42 of ih264_resi_trans_quant_sse42.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-204704614
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| platform | external_libavc | >= 12L-next:0 < 12L-next:2022-06-01 | 12L-next:2022-06-01 |
| platform | external_libavc | >= 12L:0 < 12L:2022-06-01 | 12L:2022-06-01 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6jr6-7jrx-9wjj: In ih264_resi_trans_quant_4x4_sse42 of ih264_resi_trans_quant_sse42
ghsa_unreviewed·2022-06-16
CVE-2022-20202 [MEDIUM] CWE-787 GHSA-6jr6-7jrx-9wjj: In ih264_resi_trans_quant_4x4_sse42 of ih264_resi_trans_quant_sse42
In ih264_resi_trans_quant_4x4_sse42 of ih264_resi_trans_quant_sse42.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-204704614
OSV
CVE-2022-20202: In ih264_resi_trans_quant_4x4_sse42 of ih264_resi_trans_quant_sse42
osv·2022-06-01
CVE-2022-20202 CVE-2022-20202: In ih264_resi_trans_quant_4x4_sse42 of ih264_resi_trans_quant_sse42
In ih264_resi_trans_quant_4x4_sse42 of ih264_resi_trans_quant_sse42.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-06-15
Published