Input validation error in Google Android - CVE-2019-20780

 

Input validation error in Google Android - CVE-2019-20780

Published: April 17, 2020 / Updated: August 8, 2020


Vulnerability identifier: #VU34454
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-20780
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. Certain security settings, related to whether packages are verified and accepted only from known sources, are mishandled. The LG ID is LVE-SMP-190002 (April 2019).


Affected software

Google Android

How to mitigate CVE-2019-20780

Install update from vendor's website.


External References

Related Security Bulletins