#VU28270 Out-of-bounds write in Google Android - CVE-2020-0094
Published: May 27, 2020
Google Android
Description
The vulnerability allows a local user to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input within the Media framework functionality in "setImageHeight" and "setImageWidth" of ExifUtils.cpp. A local user can trigger out-of-bounds write and execute arbitrary code on the target system with elevated privileges.