#VU25367 Out-of-bounds read in Google Android - CVE-2020-0020
Published: February 14, 2020
Google Android
Description
The vulnerability allows a local attacker to gain access to potentially sensitive information.
The vulnerability exists within the Framework functionality of Android due to a boundary condition in "getAttributeRange" of "ExifInterface.java" when the vulnerable software fails to redact location information from media files. A local attacker can trigger out-of-bounds read error and read contents of memory on the system.