CVE-2019-2137 PUBLISHED

In the endCall() function of TelecomManager.java, there is a possible Denial of Service due to a missing permission check. This could lead to local denial of access to Emergency Services with User execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-132438333.

EPSS 0.02% · 3.4th percentile

Risk Scores

EPSS Score
0.02%
3.4th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSandroid-platform-frameworks-native1:6.0.0+r26-2, 1:6.0.1+r16-1, 0
Ubuntu:20.04:LTSandroid-framework-236.0.1+r72-5, 0
Ubuntu:24.04:LTSandroid-framework-236.0.1+r72-6ubuntu1, 0, 6.0.1+r72-6
Ubuntu:20.04:LTSandroid-platform-frameworks-native0, 1:8.1.0+r23-2build1, 1:8.1.0+r23-2
Ubuntu:22.04:LTSandroid-platform-frameworks-native1:10.0.0+r36-1, 0
Ubuntu:18.04:LTSandroid-platform-frameworks-native1:7.0.0+r33-1, 1:8.1.0+r23-2~18.04, 0
Ubuntu:24.04:LTSandroid-platform-frameworks-native1:10.0.0+r36-1, 0
Ubuntu:22.04:LTSandroid-framework-230, 6.0.1+r72-6
Ubuntu:18.04:LTSandroid-framework-230, 6.0.1+r72-3, 6.0.1+r72-4

Timeline

References

Open in Interactive Console →