Information disclosure in Google Android - CVE-2019-2104

 

Information disclosure in Google Android - CVE-2019-2104

Published: July 8, 2019 / Updated: August 8, 2020


Vulnerability identifier: #VU35738
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-2104
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to gain access to sensitive information.

In HIDL, safe_union, and other C++ structs/unions being sent to application processes, there are uninitialized fields. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Android ID: A-131356202


Affected software

Google Android

How to mitigate CVE-2019-2104

Install update from vendor's website.


External References

Related Security Bulletins