CVE-2022-20393 PUBLISHED CVSS 5.5 MEDIUM

In extract3GPPGlobalDescriptions of TextDescriptions.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure from the media server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LAndroid ID: A-233735886

EPSS 0.02% · 4.3th percentile

Risk Scores

CVSS v3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.02%
4.3th percentile

Affected Products

VendorProductVersions
n/aAndroidAndroid-11 Android-12 Android-12L
googleandroid11.0, 12.0, 12.1

Timeline

References

Open in Interactive Console →