CVE-2022-20445
published 2022-11-08CVE-2022-20445: In process_service_search_rsp of sdp_discovery.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.44%
35.3th percentile
In process_service_search_rsp of sdp_discovery.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-225876506
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | packages_modules_bluetooth | >= 13:0 < 13:2022-11-01 | 13:2022-11-01 |
| platform | system_bt | >= 10:0 < 10:2022-11-01 | 10:2022-11-01 |
| platform | system_bt | >= 11:0 < 11:2022-11-01 | 11:2022-11-01 |
| platform | system_bt | >= 12:0 < 12:2022-11-01 | 12:2022-11-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r3gx-qqx9-hjg9: In process_service_search_rsp of sdp_discovery
ghsa_unreviewed·2022-11-09
CVE-2022-20445 [HIGH] CWE-125 GHSA-r3gx-qqx9-hjg9: In process_service_search_rsp of sdp_discovery
In process_service_search_rsp of sdp_discovery.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-225876506
OSV
CVE-2022-20445: In process_service_search_rsp of sdp_discovery
osv·2022-11-01
CVE-2022-20445 CVE-2022-20445: In process_service_search_rsp of sdp_discovery
In process_service_search_rsp of sdp_discovery.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Android
CVE-2022-20445: Android Security Bulletin 2022-11-01
CVE: CVE-2022-20445
Severity: HIGH
Type: ID
Affected AOSP versions: 10, 11, 12, 12L, 13
References: A-225876506
vendor_android·2022-11-01·CVSS 7.5
CVE-2022-20445 [HIGH] CVE-2022-20445: Android Security Bulletin 2022-11-01
CVE: CVE-2022-20445
Severity: HIGH
Type: ID
Affected AOSP versions: 10, 11, 12, 12L, 13
References: A-225876506
Android Security Bulletin 2022-11-01
CVE: CVE-2022-20445
Severity: HIGH
Type: ID
Affected AOSP versions: 10, 11, 12, 12L, 13
References: A-225876506
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-11-08
Published