CVE-2019-2126
Dashboard / Vulnerabilities / CVE-2019-2126
CVE-2019-2126
Summary:
Details: In ParseContentEncodingEntry of mkvparser.cc, there is a possible double free due to a missing reset of a freed pointer. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-127702368.
References: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DQSTK442ATWJOR4TU3MR6C3N5A6NDFFN/, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U2IIA3RSYABBUCFIHXIRVUT5CTJVWWZ6/, , http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00049.html, https://source.android.com/security/bulletin/2019-08-01, https://usn.ubuntu.com/4199-1/
Affected packages
Package
Name:
Purl:
Affected ranges
Type: N/A
Events:
