In attributeBytesBase64 and attributeBytesHex of BinaryXmlSerializer.java, there is a possible arbitrary XML injection due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Metrics
Affected Vendors & Products
References
History
Tue, 17 Dec 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:12.1:*:*:*:*:*:*:* cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:* |
Fri, 16 Aug 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Google
Google android |
|
Weaknesses | CWE-190 CWE-91 |
|
CPEs | cpe:2.3:o:google:android:12.0:-:*:*:*:*:*:* cpe:2.3:o:google:android:12.0l:*:*:*:*:*:*:* cpe:2.3:o:google:android:13.0:-:*:*:*:*:*:* cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:* |
|
Vendors & Products |
Google
Google android |
|
Metrics |
cvssV3_1
|
Thu, 15 Aug 2024 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In attributeBytesBase64 and attributeBytesHex of BinaryXmlSerializer.java, there is a possible arbitrary XML injection due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: google_android
Published: 2024-08-15T21:56:33.151Z
Updated: 2024-08-16T14:07:11.752Z
Reserved: 2024-05-07T20:40:55.716Z
Link: CVE-2024-34740
Vulnrichment
Updated: 2024-08-16T14:06:34.337Z
NVD
Status : Analyzed
Published: 2024-08-15T22:15:06.753
Modified: 2024-12-17T17:55:29.123
Link: CVE-2024-34740
Redhat
No data.