In flattenString8 of Sensor.cpp, there is a possible information disclosure of heap memory due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0, Android-8.1, Android-9, and Android-10 Android ID: A-141890807

Published at
2020-01-08
739 days ago
Modified
2020-01-29
718 days ago
2020
Year
The year of the turtle

https://source.android.com/security/bulletin/2020-01-01

CONFIRM:https://source.android.com/security/bulletin/2020-01-01

Vulnerability RAW

{
	"Title": {
		"_text": "CVE-2020-0007"
	},
	"Notes": {
		"Note": [
			{
				"_text": "In flattenString8 of Sensor.cpp, there is a possible information disclosure of heap memory due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0, Android-8.1, Android-9, and Android-10 Android ID: A-141890807"
			},
			{
				"_text": "2020-01-08"
			},
			{
				"_text": "2020-01-29"
			}
		]
	},
	"CVE": {
		"_text": "CVE-2020-0007"
	},
	"References": {
		"Reference": {
			"URL": {
				"_text": "https://source.android.com/security/bulletin/2020-01-01"
			},
			"Description": {
				"_text": "CONFIRM:https://source.android.com/security/bulletin/2020-01-01"
			}
		}
	}
}