CVE-2022-20353
published 2022-08-10CVE-2022-20353: In onSaveRingtone of DefaultRingtonePreference.java, there is a possible inappropriate file read due to improper input validation. This could lead to local…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.10%
0.8th percentile
In onSaveRingtone of DefaultRingtonePreference.java, there is a possible inappropriate file read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-221041256
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | packages_apps_settings | >= 10:0 < 10:2022-08-01 | 10:2022-08-01 |
| platform | packages_apps_settings | >= 11:0 < 11:2022-08-01 | 11:2022-08-01 |
| platform | packages_apps_settings | >= 12:0 < 12:2022-08-01 | 12:2022-08-01 |
| platform | packages_apps_settings | >= 12L:0 < 12L:2022-08-01 | 12L:2022-08-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2m3c-5w7m-6xgx: In onSaveRingtone of DefaultRingtonePreference
ghsa_unreviewed·2022-08-11
CVE-2022-20353 [MEDIUM] CWE-20 GHSA-2m3c-5w7m-6xgx: In onSaveRingtone of DefaultRingtonePreference
In onSaveRingtone of DefaultRingtonePreference.java, there is a possible inappropriate file read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-221041256
OSV
CVE-2022-20353: In onSaveRingtone of DefaultRingtonePreference
osv·2022-08-01
CVE-2022-20353 CVE-2022-20353: In onSaveRingtone of DefaultRingtonePreference
In onSaveRingtone of DefaultRingtonePreference.java, there is a possible inappropriate file read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Android
CVE-2022-20353: Android Security Bulletin 2022-08-01
CVE: CVE-2022-20353
Severity: HIGH
Type: ID
Affected AOSP versions: 10, 11, 12, 12L
References: A-221041256
[2]
[
vendor_android·2022-08-01·CVSS 5.5
CVE-2022-20353 [MEDIUM] CVE-2022-20353: Android Security Bulletin 2022-08-01
CVE: CVE-2022-20353
Severity: HIGH
Type: ID
Affected AOSP versions: 10, 11, 12, 12L
References: A-221041256
[2]
[
Android Security Bulletin 2022-08-01
CVE: CVE-2022-20353
Severity: HIGH
Type: ID
Affected AOSP versions: 10, 11, 12, 12L
References: A-221041256
[2]
[3]
[4]
[5]
[6]
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-08-10
Published