Out-of-bounds write in Google Android - CVE-2020-0470
Published: May 30, 2023
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to a boundary error within the extend_frame_highbd() function in restoration.c in Media framework. A remote attacker can trick the victim to open a specially crafted file, trigger an out-of-bounds write and gain access to sensitive information.
Affected software
SUSE Linux Enterprise Real Time 15
openSUSE Leap
libaom0-debuginfo
libaom0
libaom0-32bit-debuginfo
libaom0-32bit
libaom-debugsource
How to mitigate CVE-2020-0470
libaom0-debuginfo - update to 1.0.0-150200.3.15.1
libaom0 - update to 1.0.0-150200.3.15.1
libaom0-32bit-debuginfo - update to 1.0.0-150200.3.15.1
libaom0-32bit - update to 1.0.0-150200.3.15.1
libaom-debugsource - update to 1.0.0-150200.3.15.1