CVE-2022-20224
published 2022-07-13CVE-2022-20224: In AT_SKIP_REST of bta_hf_client_at.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.25%
66.0th percentile
In AT_SKIP_REST of bta_hf_client_at.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure in the Bluetooth stack with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-220732646
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| imagemagick | imagemagick | >= 0 < 8:6.9.10.23+dfsg-2.1ubuntu11.4+esm1 | 8:6.9.10.23+dfsg-2.1ubuntu11.4+esm1 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.1+esm1 | 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.1+esm1 |
| platform | system_bt | >= 10:0 < 10:2022-07-01 | 10:2022-07-01 |
| platform | system_bt | >= 11:0 < 11:2022-07-01 | 11:2022-07-01 |
| platform | system_bt | >= 12:0 < 12:2022-07-01 | 12:2022-07-01 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2022-20224: Android Security Bulletin 2022-07-01
CVE: CVE-2022-20224
Severity: HIGH
Type: ID
Affected AOSP versions: 10, 11, 12, 12L
References: A-220732646
vendor_android·2022-07-01·CVSS 7.5
CVE-2022-20224 [HIGH] CVE-2022-20224: Android Security Bulletin 2022-07-01
CVE: CVE-2022-20224
Severity: HIGH
Type: ID
Affected AOSP versions: 10, 11, 12, 12L
References: A-220732646
Android Security Bulletin 2022-07-01
CVE: CVE-2022-20224
Severity: HIGH
Type: ID
Affected AOSP versions: 10, 11, 12, 12L
References: A-220732646
OSV
imagemagick vulnerabilities
osv·2022-11-24·CVSS 5.5
CVE-2021-20224 imagemagick vulnerabilities
imagemagick vulnerabilities
USN-5736-1 fixed vulnerabilities in ImageMagick. This update provides the
corresponding updates for Ubuntu 20.04 ESM and Ubuntu 22.04 ESM. One of the
issues, CVE-2021-20224, only affected Ubuntu 20.04 ESM, while
CVE-2021-20245, CVE-2021-3574, CVE-2021-4219 and CVE-2022-1114 only
affected Ubuntu 22.04 ESM.
Original advisory details:
It was discovered that ImageMagick incorrectly handled certain values
when processing PDF files. If a user or automated system using ImageMagick
were tricked into opening a specially crafted PDF file, an attacker could
exploit this to cause a denial of service. This issue only affected Ubuntu
14.04 ESM, Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2021-20224)
Zhang Xiaohui discovered that ImageMagick incorrectly handled certain
val
GHSA
GHSA-vmwq-gw9g-wqfq: In AT_SKIP_REST of bta_hf_client_at
ghsa_unreviewed·2022-07-14
CVE-2022-20224 [HIGH] CWE-125 GHSA-vmwq-gw9g-wqfq: In AT_SKIP_REST of bta_hf_client_at
In AT_SKIP_REST of bta_hf_client_at.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure in the Bluetooth stack with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-220732646
OSV
CVE-2022-20224: In AT_SKIP_REST of bta_hf_client_at
osv·2022-07-01
CVE-2022-20224 CVE-2022-20224: In AT_SKIP_REST of bta_hf_client_at
In AT_SKIP_REST of bta_hf_client_at.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure in the Bluetooth stack with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-07-13
Published