In attributeBytesBase64 and attributeBytesHex of BinaryXmlSerializer.java, there is a possible arbitrary XML injection due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Metrics
Affected Vendors & Products
References
History
Fri, 16 Aug 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Google
Google android |
|
Weaknesses | CWE-190 CWE-91 |
|
CPEs | cpe:2.3:o:google:android:12.0:-:*:*:*:*:*:* cpe:2.3:o:google:android:12.0l:*:*:*:*:*:*:* cpe:2.3:o:google:android:13.0:-:*:*:*:*:*:* cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:* |
|
Vendors & Products |
Google
Google android |
|
Metrics |
cvssV3_1
|
Thu, 15 Aug 2024 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In attributeBytesBase64 and attributeBytesHex of BinaryXmlSerializer.java, there is a possible arbitrary XML injection due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: google_android
Published: 2024-08-15T21:56:33.151Z
Updated: 2024-08-16T14:07:11.752Z
Reserved: 2024-05-07T20:40:55.716Z
Link: CVE-2024-34740
Vulnrichment
Updated: 2024-08-16T14:06:34.337Z
NVD
Status : Awaiting Analysis
Published: 2024-08-15T22:15:06.753
Modified: 2024-08-19T13:00:23.117
Link: CVE-2024-34740
Redhat
No data.