Input validation error in Google Android - CVE-2019-20784

 

Input validation error in Google Android - CVE-2019-20784

Published: April 17, 2020 / Updated: August 8, 2020


Vulnerability identifier: #VU34457
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-20784
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to manipulate data.

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 (MTK chipsets) software. Interaction of GPS with 911 emergency calls is mishandled. The LG ID is LVE-SMP-180012 (January 2019).


Affected software

Google Android

How to mitigate CVE-2019-20784

Install update from vendor's website.


External References

Related Security Bulletins