CVE-2022-20346
published 2022-08-10CVE-2022-20346: In updateAudioTrackInfoFromESDS_MPEG4Audio of MPEG4Extractor.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to…
PriorityP431medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.41%
33.6th percentile
In updateAudioTrackInfoFromESDS_MPEG4Audio of MPEG4Extractor.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-230493653
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_av | >= 10:0 < 10:2022-08-01 | 10:2022-08-01 |
| platform | frameworks_av | >= 11:0 < 11:2022-08-01 | 11:2022-08-01 |
| platform | frameworks_av | >= 12:0 < 12:2022-08-01 | 12:2022-08-01 |
| platform | frameworks_av | >= 12L:0 < 12L:2022-08-01 | 12L:2022-08-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9253-hfmm-mch5: In updateAudioTrackInfoFromESDS_MPEG4Audio of MPEG4Extractor
ghsa_unreviewed·2022-08-11
CVE-2022-20346 [MEDIUM] CWE-125 GHSA-9253-hfmm-mch5: In updateAudioTrackInfoFromESDS_MPEG4Audio of MPEG4Extractor
In updateAudioTrackInfoFromESDS_MPEG4Audio of MPEG4Extractor.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-230493653
OSV
CVE-2022-20346: In updateAudioTrackInfoFromESDS_MPEG4Audio of MPEG4Extractor
osv·2022-08-01
CVE-2022-20346 CVE-2022-20346: In updateAudioTrackInfoFromESDS_MPEG4Audio of MPEG4Extractor
In updateAudioTrackInfoFromESDS_MPEG4Audio of MPEG4Extractor.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
Android
CVE-2022-20346: Android Security Bulletin 2022-08-01
CVE: CVE-2022-20346
Severity: HIGH
Type: ID
Affected AOSP versions: 10, 11, 12, 12L
References: A-230493653
[2]
vendor_android·2022-08-01·CVSS 6.5
CVE-2022-20346 [MEDIUM] CVE-2022-20346: Android Security Bulletin 2022-08-01
CVE: CVE-2022-20346
Severity: HIGH
Type: ID
Affected AOSP versions: 10, 11, 12, 12L
References: A-230493653
[2]
Android Security Bulletin 2022-08-01
CVE: CVE-2022-20346
Severity: HIGH
Type: ID
Affected AOSP versions: 10, 11, 12, 12L
References: A-230493653
[2]
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-08-10
Published